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Abstract 

We extend a fragment of the programming language ML by incorporating a more general 
form of record pattern matching and providing for user-declared subtypes. Together, these 
two enhancements may be used to support a restricted object-oriented programming style. 
In keeping with the framework of ML, we present typing rules for the language, and develop 
a type inference algorithm. We prove that the algorithm is sound with respect to the typing 
rules, and that it infers a most general typing for every typable expression. 
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Chapter 1 

Introduction 

1.1 Type Inference and Object-Oriented Programming 

During the past decade, a programming style known as "object-oriented" programming has 
become the basis for several popular programming languages, including Smalltalk [GR83] 
and C ++ [Str86]. In this programming methodology, the basic building blocks are objects, 
which are grouped together in classes of similar objects. There is a hierarchy of classes, 
where more specialized objects of a class constitute subclasses; importantly, operations 
defined on a class can be inherited, or automatically used, by objects of any subclass. 
Furthermore, the representation of objects and the associated class operations can be hidden 
from the outside world. These features of inheritance and information hiding are often 
regarded as central to object-oriented programming. 

Another class of programming languages consists of strongly typed languages, in which 
every expression has a type that can be checked at compile-time. These languages, such as 
Pascal and CLU, are desirable because, among other things, they guarantee that a certain 
class of errors known as type errors will not arise at run-time. Some drawbacks of traditional 
strongly typed languages are that they require the programmer to declare the types of all 
variables, and require the same function to be redefined over different types. However, in 
languages that support type inference, the types of all variables and expressions can be 
inferred by the compiler from the surrounding context, and thus can be omitted by the 
programmer. Moreover, the inferred types are "most general" types, from which all valid 
types can be easily derived. Languages with type inference thus provide greater flexibility 
and expressive power than traditional strongly typed languages, while maintaining the same 
guarantees on run- time behavior. ML [Mil85], a functional language that is based on the 
simply typed lambda calculus, is the paradigmatic language with type inference. 

Combining strong-typing and object-oriented programming clearly has many advan- 
tages, and in the past few years, there has been much research on extending strongly typed 
languages to support an object-oriented programming style [Car84, Mit84, Wan87, Sta88, 
JM88, Rem89] by incorporating some form of subtyping to model subclass relations. How- 
ever, extending languages with type inference in this manner can pose two serious problems: 
there may be no single "most general" typings, or worse yet, the type inference problem 
may become undecidable. 



1.2 Background and Results 

The viewpoint developed by [Car84] and adopted by many others [Wan87, Sta88, JM88, 
Rem89] is to think of an object as a record consisting of a finite set of labeled, typed fields. 
Inheritance is modeled by allowing a function defined on a record to be used automatically 
on a record with more fields. More specifically, the "subclass" relation is that a record type 
y is a subtype of record type x if y has at least all of the fields of x, and perhaps more. 

Although viewing objects as records captures some of the "object-oriented" behavior 
that we want, it does not permit information hiding. For this reason, it seems that a more 
useful perspective is to think of objects as some form of abstract data types. For exam- 
ple, we can think of objects as "ML-style" abstract data types, which have an associated 
name, a hidden representation, and associated operations whose implementation is hidden. 
Importantly, the types of these operations do not reveal the underlying representation of 
the abstract type; they only refer to the abstract type by name. In order to support both 
inheritance and information hiding in this framework, we want objects of any subtype to 
be able to use these operations automatically, without revealing the representation of the 
subtype. Thus, in this scenario, it seems that we need some mechanism to declare explicitly 
the subtyping relations between the names of abstract types in order to get the sort of 
subtyping behavior that we desire. Some relevant work, which we believe can be extended 
to support subtyping between abstract type names, is [Mit84], which develops a type sys- 
tem and algorithm for inferring most general types for pure lambda terms in the context of 
subtype declarations. In [Mit84], the system of subtyping relations between simple types 
is referred to as "atomic subtyping," and can be thought of as a more general form of 
"bounded quantification" [CW85]. 

There has been quite a bit of work done recently on developing systems with subtyping 
of records. The seminal work on this topic, [Car84], provides a set of typing rules for a type 
system with record subtyping and presents a type-checking algorithm for that language. 
However, the programmer is required to declare the types of all variables, and type inference 
is not provided. 

[Wan87] has the a similar sort of "subtype" relation among record types as [Car84], but 
a somewhat different set of typing rules, and he does provide an algorithm for type inference. 
The main technical innovations are the introduction of "row variables", which allow more 
flexibility in the typing of records, and an extension of unification [Rob65] that supports 
row variables. However, due to some technical problems, single most general typings do not 
exist for some typable terms in the system of [Wan87]; in fact, the typing algorithm has to 
infer a (finite) set of most general typings. 

In [JM88], we extend the atomic subtyping system of [Mit84] to support base types and 
show that it can be merged in a natural manner with a system of rules for deriving record 
subtyping that is similar to that of [Wan87]. We define our language ML + , which is an 
extension of a kernel of the programming language ML, and a type inference algorithm for 
ML + , which uses an extension of unification similar to that of [Wan87]. We show that our 
algorithm infers only types derivable by our type system, and generates single most general 
typings. Importantly, by imposing a minor restriction on records, we correct the technical 
difficulties of [Wan87]; we believe that our paper was the first published work to do so. This 
thesis revises some of the material presented in [JM88] and develops it in more detail. 

The ML + language is based on a functional subset of ML that includes built-in constants, 
records, and function abstraction using pattern matching constructs to decompose records 
into their constituents. For the sake of simplicity, we do not include the polymorphic 



"let" construct of ML, since it can be regarded as syntactic sugar. Although there are 
some algorithmic issues of dealing efficiently with the "let" construct, we do not address 
them here. We do not include variant records (tagged unions), although we believe that 
the subtyping of variants involves issues closely related to the subtyping of records [Car84, 
Wan87, Sta88, Rem89]. We would expect that incorporating variants into our system would 
not cause any serious difficulties, but we do anticipate that there would be some technical 
overhead involved. 

We extend this kernel of ML two ways. We develop a form of "extended pattern match- 
ing" that allows us we type records in a way that allows a function on records to be applied 
to every record containing some minimum set of required fields. More specifically, we in- 
troduce expression variables denoting elements of Wand's "rows." These may be bound 
by pattern matching to sequences of labeled values (parts of records). Using this extended 
pattern matching, we may define functions that operate "anonymously" on parts of records 
without knowing the names of the fields involved. In keeping with the spirit of ML, this 
form of extended pattern matching eliminates the need for conditional statements to decom- 
pose arguments passed to functions, and we have developed some rather elaborate technical 
machinery in our system in order to support this expressive power. 

Our second extension to ML involves subtyping relations between atomic types. For 
built-in atomic types such as int and bool, subtyping relationships such as int C real must 
be specified as part of the language design. As mentioned earlier, our treatment of subtyping 
extends the system for atomic subtyping developed in [Mit84]. It is our hope that this form 
of subtyping combined with record subtyping will provide a framework for subtyping among 
abstract types. 

Some examples will illustrate the flavor of ML + . Following Standard ML, function ex- 
pressions (lambda abstractions) are written f n P =>• M, where P is a pattern, often resem- 
bling a record expression, and M is any expression. For example, a function / incrementing 
the a field of a record may be written as 

fn {a = x; v} =>- {a = x + 1; v} (/) 

Essentially, the pattern {a = x; v} matches any record with an a field, binding x to the 
value of a, and binding v to any finite mapping from labels to values extending a = x. One 
type of this function in ML + is 

{a: int; NULL} -► {a: int; NULL} 

where NULL indicates that the record contains exactly the fields specified, since / clearly 
maps records with exactly an a: int field to records with exactly an a: int. Another type of 
/ is written 

{a: int; X} — >■ {a: int; X} 

where X is a "row" variable denoting a sequence of labeled types. The row variable X in 
this type expression is implicitly universally quantified, so this typing "says" that / has 
type {a: int; X}^{a: int; X} for any row X. In particular, / has type 

{a: int, b: bool, c: string}— >{a: int, b: bool, c: string} 

since b: bool, c: string is a possible value for X . Thus, if we apply / to the record {a = 1 , b = 
true,c = "extra"}, then the "extension" variable v is bound to b = true,c = "extra", and 
the result of the function application is 

/({a = 1,6 = true,c = "extra"}) — {a = 2,6 = true,c — "extra"} 



As mentioned earlier, the use of row variables to describe the inherent polymorphism 
of record operations is due to Wand [Wan87]. One technical difficulty is that A" in a type 
{a: int; A'}-* . . . should not denote a row giving a type to a, since then the type of a might 
be multiply-defined. This leads to certain subtle considerations in our typing algorithm, 
and also the point of departure from Wand's previous work. While Wand allowed type 
expressions with multiple occurrences of field names (using order of occurrence to determine 
precedence), this in fact leads to a set of most general typings. In a sense, the difficulty 
with Wand's algorithm begins with his expression language. Wand's with expression has 
two informal readings: the expression x with a: = 3 has the effect of either modifying the a 
field of x if there is one, or adding one if there is not. From a type checking point of view, it 
is not clear whether we should assume x has an a field or not, and so there are two typings 
to consider. 

We avoid these technical problems associated with Wand's language by restricting well- 
formed record types not to contain duplicate labels, and by using extended pattern matching 
instead of with. Together, these two restrictions avoid the ambiguity of Wand's expressions 
by compelling the programmer to choose which interpretation he wants his expression to 
have. For example, the expression Xx. x with a: — 3 in Wand's system translates to two 
expressions in ML + , namely fn {a — y; u} => {a = 3; u} and fn {u} => {a — 3; u}. The first 
expression constrains the argument record to have an a field, while the second expression 
constrains the argument record not to have an a field. This contrasts with the expression 
in Wand's system, which allows a record either with or without an a field to be passed as 
an argument. Aside from translating ambiguous expressions in Wand's language to sets of 
expressions, ML + retains all of the expressive power of Wand's system, while generating 
single most general typings. We note that this expressive power is due to pattern matching; 
making a similar restriction on the records in Wand's system would greatly restrict the 
expressive power of that language. For example, the expression Xx. x with a: — x.a + 1 
in Wand's system would not be typable with this restriction, since the result would have 
two a fields. However, by using extended pattern matching, we can write this expression in 
ML + as fn {a = y; u} =>• {a = y + 1; u}. 

Furthermore, there are some expressions that we can write in ML + that are not express- 
ible in Wand's language. One such sort of expression that we can write in ML + is 

fn {a = y;u} =$■ {u} 

which allows some fields of a record to be "forgotten". Another such expression in ML + is 

fn {a = y; EMPTY} => y 

where the EMPTY indicates that the record has exactly an a field. Although Wand's lan- 
guage can conceivably be extended to have this expressive power, there are some problems. 
First, it seems difficult, and perhaps even impossible, to define and type a "forget" op- 
eration that forgets all occurrences of a given field, including those fields that have been 
overwritten. Second, an operation "exactly" that restricts a record to have exactly a certain 
set of fields has precisely the same sort of ambiguity with respect to overwritten fields as 
that of the with construct, and thus also leads to a set of most general typings. 

1.3 Related Research and Future Directions 

Between the time that [JM88] was published and the time that this thesis was completed, 
Remy [Rem89] has resolved some of the technical difficulties of [Wan87] without imposing 



any restrictions on duplicate fields in records, and his system also incorporates variants 
and recursive types. The main technical innovation is a new perspective on records in the 
context of a finite set of labels. All records are assumed to contain fields corresponding to 
all labels in the (finite) set; however, only some of the fields need to contain values. The 
fields that do not contain values are considered to be "uninitialized" , but must be written 
out explicitly. However, in a more recent paper [Wand89], Wand extends Remy's system 
to an infinite set of labels using row variables, so that only the fields that play a role in a 
certain expression need be written explicitly. 

Remy's type system is richer than both the system of [Wan87] and our system without 
atomic subtyping. In fact, in Remy's system, all of the typable expressions in the language 
of [Wan87] have single most general typings. Moreover, if we omit atomic subtyping from 
our system, then all expressions that are typable in our system can be translated into Remy's 
language and typed in his system. In particular, expressions corresponding to "forgetting" 
fields of a record can be translated directly, while expressions denoting that a record must 
have exactly a certain set of (initialized) fields can be translated into a straightforward 
extension of his language. Furthermore, Remy's system can type expressions that are not 
typable in either the system of [Wan87] or our complete system. For example, his approach 
would assign to the expression 1 

if x then {a = 3, b = true} else {a = 5} 

the record type such that a may be considered to be an integer field, and all other fields 
are "uninitialized", since the records {a = 3, b — true} and {a — 5} are unifiable in his 
system. However, under both our approach and the approach of [Wan87], these records are 
not unifiable, and thus, this expression would not be typable. 

The system of [Wan87] is a special case of Remy's system, but the relationship is more 
complicated for ML + . Although any ML+ expression that is typable without atomic sub- 
typing can be translated into a typable expression in Remy's language, our system without 
atomic subtyping is not a special case of Remy's system. The typing that Remy's system 
generates on a translated ML + expressions does not translate back into the typing that 
our system yields; specifically, Remy's typings cannot capture the constraint that records 
cannot have duplicate labels anywhere in the typing derivation of an expression. (As will 
become apparent in following chapters of this thesis, our typings capture this constraint by 
explicitly stating the set of types that appear in the derivation of an expression, but do not 
appear in the final typing statement.) 

In fact, our system without atomic subtyping distinguishes a larger class of type errors 
than that of Remy's system. For example, our type inference algorithm generates a type 
error if the function fn {u} =>• {a = 3; u} is applied to a record with an a field, thus 
avoiding the situation in which a programmer unwittingly overwrites a field. Since at this 
moment it is unclear what sorts of languages and type systems are desirable for object- 
oriented programming, it may turn out later on that the larger class of type errors in ML + 
is advantageous to programmers. The above example shows that there is some question as 
to whether the ambiguous expressions in Wand's system should be typable. 

On the other hand, language designers may consider the system of [Rem89] more desir- 
able than our system, since Remy's system types more expressions than ours, his system 



Although an "if" statement is not directly expressible is some of the languages discussed here, it is a 
simple matter to type such a statement. Namely, the if-clause must be a boolean, and both arms of the 
statement must have a "least" type in common. 



incorporates variants and recursive types, and his type inference algorithm uses the usual 
unification algorithm rather than the extension to unification developed in [Wan87]. Thus, 
anyone wishing to implement a language with type inference that supports automatic sub- 
typing between records should probably not consider the type system and type inference 
algorithm presented in this thesis, but instead, should adopt the system of [Rem89] ex- 
tended to an infinite set of labels as in [Wand89]. It is important to point out, though, that 
Remy has not incorporated atomic subtyping into his system. Although it is quite possible 
that atomic subtyping can be merged naturally into Remy's system, a serious student of the 
subject may wish to read our work in order to get some insights into how it can be done. 

In addition to the three papers discussed in detail above, a host of other papers on this 
topic have been published in the past few years [Sta88, OB88, Wand89, FM88, CCHM089], 
presenting different languages, type systems, and type inference algorithms that support 
various "object-oriented" features. We give a brief comparison of these systems here. 

If we only consider the core language consisting of variables, records, lambda abstraction, 
and function application in all the systems, then the system of [Car84] is incomparable with 
the system of [Wan87] and our system. For example, the [Car84] approach would assign 
the expression 

if x then {a: = 3,6: = true} else {a: = 5,6: = Xx. x} 

the type {a: int}, since this is the least upper bound of the record types {a: = 3,6: = true} 
and {a: = 5,6: = Xx. x}. However, under both our approach and the approach of [Wan87], 
these records are not unifiable, and thus, this expression is not typable. On the other hand, 
in Cardelli's system, one cannot translate into a typable expression an expression like 

((Ax. x with a: — x.a + l){a: = 3,1: — y})-l 

where I is an arbitrary label. In Cardelli's system, the type of a lambda-bound variable 
must be declared, and since there is no mechanism to express the "rest of a record", the 
type of a lambda-bound record must have a certain fixed set of fields. Thus, the argument 
record must be coerced to have that same fixed set of fields, and, in general, applying a 
function to a record with more fields results in the loss of the "extra" fields. 

Although the basic system of [Rem89] discussed earlier in this section is incomparable 
to that of [Car84] for the same reasons discussed above, it seems that an extension to 
Remy's basic system can type all the expressions typable in the system of [Car84], as well 
as all the expressions typable in the system of [Wan87]. However, in this system, one 
cannot express the notion of restricting a record to have exactly a certain set of fields, 
and thus, this extended system cannot type all the expressions typable in ML + (without 
atomic subtyping). At any rate, this extension to Remy's system is merely sketched, and 
not worked out in detail, in [Rem89]. 

A type inference algorithm for a language based on [Car84] is presented in detail in 
[Sta88], which generates a set of subtype relations between records that are satisfied when- 
ever a typing for an expression is derivable. He does not, however, present an algorithm 
that checks the satisfiability of sets of such subtype relations, and his principal types may 
be empty. As a consequence, given an untypable expression, his algorithm does not neces- 
sarily indicate that no typing exists for that expression. Furthermore, like that of [Car84], 
Stansifer's language does not contain any general mechanism for record extension or modi- 
fication, and so his system is also incomparable to that of [Wan87] and [JM88]. 

[OB88] presents a somewhat different core language that introduces sets, joins, and 
projections in the context of subtyping of records, and provides type inference for this 

6 



language. Because of the restrictions upon the join operation, this system is incomparable 
to that of [Wan87], [JM88], and [Rem89], since one cannot translate into the language 
expressions like Xx. x with a: = x.a + 1. Using the join operation, however, it is possible 
to translate expressions like Xx. x with a: — 3 into this language. 

[Wand89] extends the core language of [Wan87] to express record concatenation, and 
gives a treatment of classes and multiple inheritance by using syntactic sugar for this un- 
derlying language. Using the system of [Rem89] extended to an infinite set of labels, a type 
inference algorithm is given that generates a set of most general typings for this language. 
If we consider the core language of [Wand89] without record concatenation, this system is 
a special case of that of [Rem89]. 

Leaving type inference aside, [CCHM089] presents an extended form of "bounded quan- 
tification" [CW85] that seems useful when recursive type definitions and subtyping are used. 
Leaving subtyping of records aside, [FM88] presents a type inference algorithm based on 
that of [Mit84], and develops procedures for simplifying the set of subtyping assertions that 
are inferred by the algorithm. 

As is apparent from the preceding discussion, there exist a fair number of languages and 
type systems that embody some "object-oriented" features, and these systems differ from 
one another in some non-trivial technical ways. Although such a comparison is useful, it is 
important to ask some broader questions. First, which of the different features is it feasible 
to merge together with the aim of developing a more powerful "object-oriented" language? 
Second, what further extensions should we aim to develop? 

It seems to us that it is feasible to merge most of the approaches discussed above 
into one system with type inference. However, we feel that abstract data types capture 
an important property of object-oriented programming and should be incorporated into 
such typed languages. Other important features that should be considered are multiple 
inheritance, "self", and "method specialization." 

In this entire discussion, we have only considered type systems and type inference algo- 
rithms, and have not discussed whether these type systems are themselves "reasonable". It 
would be interesting and worthwhile to look at the semantics of these systems, both from 
an operational and denotational point of view. Such an investigation does not appear in 
this thesis, and the interested reader is directed towards [Kam88, BL88, Red88, Coo89, 
BCGS89]. 

1.4 Outline of Thesis 

Chapter 2 presents the syntax of ML + . The typing system of the language, which is 
specified by a set of typing axioms and inference rules, is presented in Chapter 3. The 
notion of substitutions, instances, and "most general" typings is also developed in that 
chapter. Finally, Chapter 4 presents the algorithm for inferring a most general typing for 
any expression in ML + . In that chapter, we prove that the algorithm is sound with respect 
to the type system, in the sense that whenever the algorithm gives term M type a, the 
assertion that M has type a is provable from the typing rules. We also show that the 
algorithm infers the most general type for any typable term. Specifically, if we can prove 
M has type a using the typing rules, then the algorithm succeeds in finding a typing for M 
which is "more general" than a in a precise sense developed in earlier chapters. 



Chapter 2 

ML + : Types, Syntax, and 
Notation 

2.1 Types 

We begin with an infinite set of type variables and some fixed set of base types. We fix this 
set to be {int, bool, real, string}; however, our type system and algorithm can be easily 
extended to handle a larger set of base types. 

There are two forms of structured types: function types and record types. Function 
types are written using — > as usual, so that a — ► r is the type of functions from a to r. 
As mentioned in Chapter 1, we believe that variants (tagged unions) involve issues closely 
related to records [Car84, Wan87, Sta88, Rem89], but we do not consider them here. 

Record types are written in a slightly unusual way. Intuitively, record types are finite 
functions from labels to types. In our system, part of this finite function can be named but 
unspecified, so that it can be passed around and referred to without being fully specified 
until a later time. To support this naming of parts of record types, we follow [Wan87] and 
introduce an infinite set of row variables, which denote finite functions from labels to types, 
and the row constant NULL which denotes the empty function. 

In order to make our type system and algorithm more understandable in a technical 
sense, while continuing to write our examples in ML + , we use two different notations for 
record types. In the formal notation, summarized in Table 2.3, record types are pairs (h, Z) 
where h is a finite function from labels to types and Z is either a row variable or NULL. 
We call a record type in which Z is a row variable an extended record type, and a record 
type in which Z is NULL fixed. 

In ML + , record types are written {/1.T1, . . . ,l n :T n ;Z}. For example, the record type 
{a: a, b: r; X} is intuitively the finite function that maps a to a and b to r, combined with 
the as yet unspecified function denoted by the row variable X. On the other hand, the 
record type {a: a, b: r; NULL} is intuitively the finite function that maps exactly a to a and 
6 to T. 

Since we use finite functions to write records, all of the labels in a record must be distinct. 
This distinguishes our type expressions from the expressions used in [Wan87], and leads to 
an important and slightly subtle complication in our system. To avoid the algorithmic 
inefficiencies of Wand's algorithm [Wan87], we must assume that the domains of h and Z 
(as finite functions) are disjoint. This complicates substitution of record expressions for row 
variables, since it only makes sense to replace a row variable by a record type which has 
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Table 2.1: Summary of Types 

an appropriately limited domain. To avoid incorrect substitutions, our typing algorithm 
therefore maintains restrictions on row variables. 
The types are summarized in Table 2.1. 



2.2 The Language Syntax 

ML + is derived from a subset of ML with pattern matching, function abstraction, records, 
ground constants, and built-in (possibly higher-order) constants. For the ground constants, 
we assume the set Z of integers, the set 3ff of reals, the set {true, false} of booleans, and 
an infinite set of strings. Any closed term may be incorporated into ML + as a built-in 
constant. We note here that although there is no explicit construct for declaring recursive 
functions, it is possible to define, as a built-in constant, an operator fix that returns the 
fixed-point of a function. Thus, using fix, we can define recursive functions. 

The two new features of ML + are a more powerful (extended) form of pattern match- 
ing, which permits subtyping of records, and structural subtyping, which allows subtyping 
between base types. 

Extended pattern matching is achieved using an infinite set of extension variables, which 
play a role in the language similar to that of row variables in the type system. Formally, 
extension variables denote finite functions from labels to expressions, while the extension 
constant EMPTY denotes the empty function. Analogous to record types, record expres- 
sions are pairs whose first component is a finite function from labels to expressions and 
whose second component is an extension variable or EMPTY. As with record types, we 
call a record expression whose second element is an extension variable an extended record 
expression, and one whose second element is EMPTY fixed. We do not allow record expres- 
sions with duplicate fields, thus imposing the same sort of restrictions on record expressions 
as on record types. 

Patterns are simply a proper subset of expressions, consisting recursively of ground 
constants, variables, fixed record expressions, and extended record expressions. However, 
all variables and extension variables within a pattern must be distinct. 

In ML + , as in ML, pattern matching provides a limited form of equality testing over 
the structure of types, while pattern matching over constants provides an equality test for 
ground constants. For the sake of simplicity in this thesis, we do not provide a polymorphic 
equality function since such an extension, while fairly straightforward, would add a layer of 
technical complication to our system. 





Expressions 


b 




ground constants 


q 




built-in constants 


X 




variables 


fnP^M 




abstraction 


MN 




application 


{EMPTY} 




empty fixed records 


{«} 




empty extended records 


{h = M u ... ,h = M k ] EMPTY} 


fixed records 


{k = Mi, ... ,l k = 


M k ;u} 


extended records 


where /,• 7^ /y /or 


all i ^ j 



Table 2.2: Summary of Expressions and Patterns 



The language is summarized in Table 2.2. 



2.3 Met a- not at ion 



Since there are quite a few syntactic categories to ML + , the meta-notation we use is summa- 
rized in Table 2.3. This notation will be used extensively in our proof rules and algorithm, 
while the examples will be written using ML + syntax. 
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M,N 


expressions 


b 


ground constants 


9 


built-in constants 


x,y,z 


variables 


U, V 


extension variables 


w 


variables and extension variables 


E 


extension variables and EMPTY 


f 


finite functions from labels to expressions 


(f,E) 


record expressions 


P 


patterns, namely, 


abstraction-free, application-free expressions 




with no repeated variables 




or extension variables 


<T,T 


type expressions 


c 


base types 


s,t 


type variables 


xy 


row variables 


z 


row variables and NULL 


h 


finite functions from labels to types 


(h,Z) 


record types 



Table 2.3: Summary of Notational Conventions 
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Chapter 3 

The Typing System 



3.1 Overview 

As mentioned in the introduction, the main purpose of this thesis is twofold. First, we would 
like to define a typing system for ML + that supports the form of subtyping discussed in 
Chapter 1 and Chapter 2. Since the legal terms in ML + are exactly the pre-terms in ML + 
syntax that have a typing derivable through this typing system, the typing system serves to 
define the language. Secondly, we would like to develop a type inference algorithm that is 
"equivalent" to the typing system in the sense that it generates a typing for exactly those 
terms that have a typing derivable through the typing system. Moreover, for any typable 
expression M, we want the typing algorithm to generate a "most general" typing, whose 
set of "instances" is exactly the set of provable typings for M. 

In this chapter, we present the typing system for ML + and give a precise definition of 
instances and most general typings in the context of this typing system. Our typing system 
consists of two separate but related sets of typing rules, one for deriving subtype assertions, 
which are subtype relations between types, and the other for typing expressions. 

The chapter is organized as follows. First, in Section 3.2, we present the derivation 
rules for subtype assertions. Section 3.3 defines the form of typing statements, which are 
formulas that capture the information we need in order to derive typings for expressions, 
and Section 3.4 presents a set of seemingly natural derivation rules for typing statements. In 
Section 3.5, we develop the "instance" relation in some detail and show that, in the typing 
system of Section 3.4, provable typings are not closed under the instance relation. As we 
show, this implies that "most general" typings do not exist for some expressions for which 
a type is derivable in the typing system. We examine the difficulty, and then modify the 
typing system a bit in order to get the i?-typing system, which has the technical properties 
that we need. Section 3.6 is devoted to proving Theorem 3.6.7, the main theorem of the 
chapter, which shows that, in the R- typing system, all instances of a provable typing are 
provable. Section 3.7 develops the notion of most general typings in the context of the R- 
typing system, and Section 3.8 examines how the the i?-typing system relates to the original 
typing system. 

3.2 Proof System for Subtyping Assertions 

As mentioned in the introduction, subtype assertions are of the form a C r. We require 
that the subtype relation, C, act like a pre-order on types. In particular, we follow [Mit84] 
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and introduce into our system for deriving subtype assertions the following three axioms 
and rules. 

ref 
trans 





a 


<= o- 


a 


■ C T 


, t Q 7 




a 


C7 


a 


Ca' 


, r' C r 


a'- 


-r' 


C a — * r 



arrow 

We note that the function type constructor — > is antimonotonic in the first argument and 
monotonic in the second. 

We have a similar rule for the "subtype" relation on records. 

(/i, Z) C {h , Z ) 

We say that a subtype assertion a C r is provable from a set C of subtype assertions, 
written ChcrCr, ifcrCr can be derived from assertions in C using only the typing rules 
above. We will write C h C if C h <r C r for every <r C r e C". It is easy to show that h is 
a transitive relation on sets. 

In our typing system, we restrict C to consist only of atomic subtype assertions, which 
are subtype assertions of a certain simple form. We say that a subtype assertion irCris 
atomic if 

• a and r are both type variables 

• a and r are both ground types 

• Each of a and r is a ground type or a type variable 

• Each of a and r is of the form (<f>, Z) 

We say that C is an atomic set or that C is atomic if it consists only of atomic subtype 
assertions. 

3.3 Syntax of Typing Statements 

In the typing system for expressions, the typing statements have the form 

C,AD M:o 
where 

• C is an atomic set of subtype assertions. 

• A is a finite set of associations x:a between variables and types, and associations 
u: (h,Z) between extension variables and record types. 

• M is an expression and a is a type expression. 
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The typing C,A D M:a may be read as, "Given the subtype assertions in set C and 
the assignment of types to variables and extension variables described by A, the expression 
M has the type <r." 

To allow a slightly modified form of "ML-style" polymorphism, we consider all type 
and row variables that occur in C and a but do not occur in A to be implicitly universally 
quantified. For example, the typing 

{s C /}, <p D fn x =>• x: s—*t 

should be read as, "For all types s and t such that s C t, the identity function has the 
type s-+t." We note that this form of polymorphism does not correspond to the sort of 
polymorphism that the ML "let" construct provides. 

3.4 Proof System for Typing Statements 

In this section, we present a seemingly natural set of typing rules for expressions. We begin 
with the typing axioms for ground constants, which are as follows. 

int C, A 3 b: int whenever b is an integer 

The axioms for reals, booleans, and strings are analogous, with int replaced by real, 
bool, and string, respectively. 

The typing rules for variables and application are standard. 

var C,ADx:a whenever x: a £ A 

C,AD M:a^T, C,AD N:a 



app 



C,AD MN:t 



Due to pattern matching, the typing rule for lambda abstraction is somewhat more 
complicated than usual, since lambda abstraction may bind arbitrary patterns, in addition 
to variables. The typing rule for function expressions must therefore take the typing of 
patterns into account. There is a subtle but important reversal of subtype assertions in 
the abstraction rule which seems best illustrated by a simplified example. The pattern 
{a — x, b = y} has typing 

{ s Q *}> i x - s, y.s} D {a = x,b = y}: {a: t, b: t}, 

which means that if we give x and y values of type s, and s C t, then the pattern has type 
{a:t,b:t}. However, when we lambda abstract over the pattern, we actually bind a value 
to {a = x,b = y} and access its components using variables x and y. So, in effect, we use 
the typing statement about the pattern "backwards." The simplest technical adjustment 
seems to be to reverse the set of subtype assertions before combining them with the typing 
statement for the function body. If the function body is simply x, for example, then this 
gives us the typing 

{t C s}, D fn {a — x, b = y} => x: {a: t, b:t} — > s 

while writing s C t instead would give us an incorrect typing. (An alternative is to reformu- 
late the typing rules for patterns in a way that more accurately reflects their use. However, 
the current formulation has algorithmic advantages due to the similarities with expressions.) 
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In order to state the typing rule for lambda abstraction, we need to develop some 
notation and some definitions. Since the notion of free variables is important in the typing 
rule for abstraction, we define vars(M) inductively as: 

• vars(x) = x 

. vars((f, EMPTY)) = \J l€dom(f) vars(f(l)) 

• vars({f,u)) = {J ledom{f) vars(f(l)) U {u} 

• vars(MN) — vars(M) U vars(N) 

• vars(fn P => M) = vars(M) — vars(P), where "— " is set difference 

We define vars(A) — {w | w: a £ A}, where w ranges over variables and extension variables. 
We use the notation C op for the opposite set of subtype relations, 

C op = {a C t | r C a £ C} 

and A[A'] for the result of modifying A so that every variable and extension variable men- 
tioned in A' has the type specified by A' rather than A. More precisely, A[A'] — A\ U A' , 
where A = A\ U A 2 and A 2 = {w: a | w. a £ A and w £ vars(A')}. 
The typing rule for abstraction is then as follows. 

C*,A'DP:a, C,A[A')dM:t 
abs — — — ; — —r — vars(A) = vars(P) 

The condition uars(A') = vars(P) ensures that every variable occurring in A' must 
occur in P. This is important, since we want A[A'] to modify A only on variables that 
become bound by fn. 

Proceeding to the typing rules for records, we first introduce the two axioms for records 
whose first component is the empty function. 

reel C,AD (<j>, EMPTY): <<£, NULL) 



reel C,Ad {(f), u): (h, Z) whenever u: {h, 2) £ A 

The third typing rule is for records whose first component is a non-empty function. Since 
extension variables may be assigned arbitrary record types, we have a minor complication 
since we do not want duplicate field names. To express the rule succinctly, we define the 
partial operation -(- on finite functions from labels to types as 



hi + h 2 — h s.t. h(l) = < 



hi(l) if I £ dom(h\) 

h 2 (l) if / £ dom{h 2 ) if dom(h\) n dom(h 2 ) — 

undefined otherwise 



If dom(hi) and dom(h2) are not disjoint, then hi -f h 2 is undefined. 
The third rule for records is then as follows. 

C,AD (4>,E):{h 2 ,Z), V7 £ dom(f). C,Ap f{l):hi{l) 

rec3 — — all typings well-formed 

C,A D (f,E):(h 1 + h 2 ,Z) 
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where dom(f) = dom(h\) ^ <t> 

It is worth saying a few words about the form of recS . Generally, axioms and infer- 
ence rules are written as schemes, which are "abbreviations" for all of their substitution 
instances. However, not all substitution instances of rule recS are well formed, since + 
may be undefined. Therefore, we interpret this rule "scheme" as indicating that any mean- 
ingful (well-formed) substitution instance may be used in deriving types for terms. As a 
consequence of the partiality of + , typing derivations that use recS may not be preserved 
by arbitrary substitutions, but only those which, throughout the proof, yield well-formed 
types (i.e., types that do not anywhere contain record types that have duplicate labels). 

Our typing system also allows any set of closed expressions to be built in as term 
constants, as long as each is given a proper type. For example, the type for the language 
construct if can built into the typing system as a term constant. A reasonable typing for 
if is 

<t>, 4> 3 if- bool— s-f— *t— >t 
It may seem at first glance that this typing does not capture any of the power that subtyping 
provides us; however, as we will see in Section 3.5, we can derive from the above typing 
that 

\-C,A D if:s->t 1 -+t 2 -*t', 

where C = {s C bool, !]C(, t 2 C i, t C /'}, 

and A is any type environment. Furthermore, as we shall see in Section 3.7, this second 
typing is the "most general" typing of if . 

It is useful to point out that an operator fix that returns the fixed-point of a function 
can also be defined as a built-in constant. A reasonable typing for fix is 

<f>,<j>Dfix:(t->t)^-t 

Again, we can derive the "most general" typing of fix from this above typing. 
The axiom for term constants is 

const C,ADq: Sr q whenever S is defined on r q 

where r q is the built-in type for the constant q, and the application of the substitution S 
on T g results in a well-formed type. The idea here is that since all type variables in r q are 
considered to be implicitly universally quantified, we allow different substitution instances 
of the type of a built-in constant to be used within the typing of any expression. 

Although this typing axiom gives us the desired typing for if, we may want more flex- 
ibility in building in the types of other built-in constants. More specifically, we may wish 
to incorporate into our system a typing for a (closed) term q; that is, we wish to build in 
a set C q as well as a type T q for q. Unfortunately, our system, as exists, does not seem 
to be powerful enough to handle these sorts of typings in general without sacrificing the 
property of most general typings. However, it seems that we can build in a large class of 
such typings into our system as axioms, while maintaining most general typings; we omit 
further discussion here. 

Finally, in order to make use of subtyping, we have the rule 

C, A D M: a, C h a C r 



coerce 



C,AD M:t 



By this rule, an expression may be considered to be of the type of any "supertype" of 
its actual type. 
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3.5 Substitutions, Instances, and the iMyping System 

Although the typing system in Section 3.4 seems to capture the sort of subtyping that we 
want to achieve, it turns out that, for some typable expressions, most general typings do not 
exist. As mentioned in the overview to this chapter, the problem with the typing system 
arises because, for some expressions, provable typings are not closed under the "instance" 
relation. In this section, we develop the notion of instance in some detail and define most 
general typings using this instance relation. We discuss the difficulty in the typing system 
of Section 3.4, and then modify the typing system in order to correct this difficulty. We call 
the modified typing system the i?-typing system. 

We would like to begin by straightaway discussing the notion of "instance", but as the 
basic part of the instance relation consists of a substitution, which is a finite function from 
type variables to types and from row variables to record types, we need to first discuss 
substitutions in some detail. Because a substitution may map a row variable to a record 
type (h,Z) where h is a non-empty function, applying a substitution naively may result 
in a record type containing duplicate labels. To prevent this, we will treat the process of 
applying a substitution to a type as a partial operation. 

Using the operation + developed in the previous section, we define the partial operation 
Sa, the action of a substitution S on a type a, where we write S[t] = o if S maps t to a, 
and S[X] = a if S maps X to a. Sa is defined inductively as: 

• Sc = c 

, st= { S[t] if t G dom(S) 
I t otherwise 



• 



• 



*{<!>,<<)-< ^^ otherwise 



5(0, NULL) = <0,NULL) 
S(h,Z) = 



(h; S + Ieft(S(<f>, %)), right(S{4>, Z))) if h\ S is defined and 

the + operation is defined 
undefined otherwise 



• S(a— >r) = Sa—>Sr 

It is important to note that, due to the partiality of +, the action of S on a record 
type is undefined if an ill-formed function from labels to types is created anywhere within 
the resulting record type. Since h may (recursively) map a label to a record type, the 
composition of a finite function h from labels to types with a substitution S, written h; S, 
is also a partial operation. We define h; S as: 



h;S 



h! s.t. h'{l) = { S ( h (y , if + ( G d ° m ^ h) if W € dom(h). S(h(l)) is defined 
I undefined otherwise 

undefined otherwise 



Similarly, composition of a substitution S with another substitution T, written S; T, is 
a partial operation. We define S; T as: 
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U if Vi € dom(S). T(S[t]) is defined, 

5; T = { VX € dom(S). T(S[X]) is defined 

undefined otherwise 



where dom(U) = dom(S) U dom(T), and 
and 



_ f T(£[*]) if * e dom(S) 

~" 1 T[f] if * e dom{T) and f £ dom(S) 



I T(5[^]) if A- €dom(S) 
L J \ T[*] if X e dom{T) and * £ dom(S) 

We note that if S; T is defined, then (5; T)a = T(Sa), or both are undefined. We also 
note that h; (S;T) = (h; S);T,ov both are undefined. Likewise, composition of substitutions 
is associative. 

We also define the action of a substitution S on type environments and on sets of 
possibly non-atomic subtype assertions. A substitution S applied to A is the assignment 
SA = {w.Sa | w.a € A}, where w ranges over variables and extension variables, if S is 
defined on all such a. We consider SA undefined otherwise. Similarly, the application of 
substitution S to a possibly non-atomic C is the set SC = {St\ C St2 \ t\ C t^ G C}, 
provided St{ is defined for all such r,-. Again, we consider SC undefined otherwise. 

In defining our instance relation, we could follow [Mit84] and say that a typing C", A' D 
M: a' is an instance of a typing C,AD M: a by a substitution S if S is defined on C, A, 
and a, and 

C h SC, A' D SA, and <r' - Sa 

However, since in the above definition, SC may be a non-atomic set of subtype assertions, 
we cannot use the same sort of reasoning about SC as we do for C and C. Thus, in order 
to simplify the proofs of our main theorems, we use a seemingly more complex notion of 
instance that uses, in place of SC, an atomic set S^C that is computable and that is closely 
related to SC. We show that this definition is, in fact, "equivalent" to the one above in 
the sense that C, A' D M: a' is an instance of C, A D M: a by a substitution S under the 
above definition iff it is an instance under this definition. 

The basic idea is as follows. We want to define S • C as a "least" atomic set that 
implies S • C h SC; that is, any atomic set C that implies SC should also imply S • C. It 
then follows that, for any atomic set C , C h SC iff C h S • C, and thus, the two above 
definitions of instance are equivalent. 

The reasoning we will use in defining the • operation is as follows. We will first show 
that, in order for an atomic set C" to imply SC, SC must contain only subtype assertions 
that have a certain form. We will then show how to compute, from any subtype assertion 
a C t of this form, a "least" atomic set that implies a C r. Thus, any atomic set C" that 
implies a C r must also imply this computed atomic set. Using these ideas, we will define 
■5* • C so that it has the properties outlined above. 

We begin by showing that an atomic set can imply only matching subtype assertions 
a C r, where a and r have the same syntactic form. More precisely, we define the relation 
match on types recursively as: 

• t\ matches t<i 
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• c\ matches c 2 

• t matches c, and c matches t 

• (4>,2) matches (4>,Z') 

• a matches a' and r matches r' iff a— >r matches <r'— +r'. 

• dom(h) = dom(h') and V7 6 dom(h). h(l) matches /i'(7) 
iff (h,Z) matches (h',Z f ) 

We say that a subtype assertion uCris matching if a and r match. It is easy to see 
that match is an equivalence relation on types. 

Lemma 3.5.1 If C h a C r, where C is atomic, then a matches r. 

Proof. We prove the lemma by induction on the length of the derivation of a C r 
from C. 

If the proof ofuCr from C requires no steps, then a C r G C and is thus an atomic 
subtype assertion. Therefore, a matches r. 

Otherwise, the proof must have ended in an application of either (trans), (arrow), or 
(record). If the final step was (trans), then ChtrCr must have followed by the antecedents 
a C 7 and 7 C r for some 7. Since the proofs of a C 7 and 7 C r are shorter, we may 
assume that a matches 7 and 7 matches r. Thus, by the properties of match, a matches r. 

If the final step was (arrow), then a must be of the form a — 0\^02 and r must be 
of the form r = T\— »t 2 , and C h ct C t must have followed by the antecedents T\ C (Ti 
and CT2 C r 2 . Since the proofs of T\ C o\ and ct 2 C r 2 are shorter, we may assume that T\ 
matches G\ and ct 2 matches r 2 . Thus, by the properties of of match, a matches r. 

If the final step was (record), then <r must be of the form a = (h, Z) and r must be of the 
form r = {h',Z'}, where dom(h) — dom(h') ^ <f>. Moreover, C h a C r must have followed 
by the antecedents (4>,Z) C (<f),Z'), and VZ e dom(h). h(l) C /»'(/). Since the proofs of the 
h{l) C /i'(7) are shorter, we may assume that VZ € dom(h). h{l) matches /i'(7). Thus, by the 
properties of match, a matches r, proving the lemma. ■ 

We now wish to show that for any matching subtype assertion a C r, we can compute 
an atomic set C that implies itCt, and such that for any atomic set C that implies a C r, 
C" also implies C. However, in order to justify "decomposing" a C r into atomic subtype 
assertions, we will need to use the following lemmas about the form of derivable subtype 
assertions. 

Lemma 3.5.2 For any atomic set C , C V o~\^oi C t\— >r 2 iff C \~ T\ C o\ and Ch^C 

Proof. The proof of this lemma is exactly that of [Mit84]. 

One direction is a direct consequence of rule (arrow): if C h T\ C ctx and C r- <r 2 C r 2 , 
then C h cti— >cr 2 C ti-^-t 2 . It remains to prove the converse. 

We show that if C h <r C r for any cr and r of the form cr = (Ti— ><t 2 and r = ri— >r 2 , 
then there is a proof offfCr from C that ends with an application of the rule (arrow). 
We argue by induction on the length of the proof of o C r from C. If the proof is one step, 
then this step must be an application of rule (arrow) and so, trivially, there must be a proof 
ending in an application of (arrow). 
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For the inductive step, assume that we have a proof whose final step is a use of rule 
(trans) from antecedents a C 7 and 7 C r. By Lemma 3.5.1, we know that 7 has the form 
7 = 71— >72- Since the proofs of a C 7 and and 7 C r are shorter, we may assume that we 
have proofs of these inclusions ending in applications of rule (arrow). Thus, 

C \~ 71 C cti, <r 2 C 72, ri C 7 1; 72 C r 2 . 

By rule (trans), we have C h ti C (Tj and C h <7 2 C r 2 , which proves the lemma. ■ 

We have a similar lemma for records. 

Lemma 3.5.3 For any atomic set C, C h (h,Z) C (h',Z'), where h is non-empty, iff 
dom(h) = dom(h') ^ <f> and Ch (0,2) C (0,2') and V/ G dom(h). C H /i(/) C fc'(Z). 

Proof. 

The proof of this lemma is analogous to the proof of Lemma 3.5.2. 

One direction is a direct consequence of rule (record): If dom{h) = dom(h') ^ aim 
C h {(f), Z) C (4,2') and V/ e rfom(/»). C h /i(Z) C /i'(/), then C h (/i,2) C (h',Z t ), where 
/1 is non-empty. It remains to prove the converse. 

We show that if C h a C r for any (7 and r of the form <7 = (h,2) and r = {h',Z'), 
where h is non-empty, then there is a proof of a C r from C that ends with an application 
of the rule (record). We argue by induction on the length of the proof of a C r from C. If 
the proof is one step, then this step must be an application of rule (record) and so, trivially, 
there must be a proof ending in an application of (record). 

For the inductive step, assume that we have a proof whose final step is a use of rule 
(trans) from antecedents a C 7 and 7 C r. By Lemma 3.5.1, we know that a, 7, and r 
match, and that 7 has the form 7 = (h",Z"), where dom(h) = dom(h") = dom(h'). Since 
the proofs of <r C 7 and and 7 C r are shorter than that of cr C r, we may assume that we 
have proofs of these inclusions ending in applications of rule (record). Thus, C \~ (<f>, Z) C 

(<f>,z»), c\-(<t>,z")c{<t>,z'),3Jid 

for all / e dom(h), C h /i(/) C h"(l) and C h /*"(/) C h'(l). 

By rule (trans), C h (0,2) C (0,2') and V/ € dom(h). C \- h(l) C /i'(/), which proves the 
lemma. ■ 

Using the above lemmas, we can now prove the property we desire. 

Lemma 3.5.4 Let a and r be matching type expressions. There is an atomic set C = 
ATOMIC(a C t) with C H a C r and such that if C is any atomic set of subtype assertions 
with C'hffCT, then C r- C. 

Proof. 

We define ATOMIC (cr C r) as: 

• If <T C r is an atomic subtype assertion, then ATOMIC(ct C r) = {a C r}. 

• If cr C r is of the form <ti— >ct 2 C ri— >r 2 then 

ATOMIC(a C r) = ATOMIC(ri C ffl ) U ATOMIC(a 2 C r 2 ). 
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• If a C r is of the form (h,Z) C (h\ Z'), where /i and hi are non-empty, then 

AT0MIC(<7 C r) = (J ATOMIC(/i(Z) C fc'(Z)) U ATOMIC«<£, 2) C {<f>, Z')). 

lEdom(h) 

Let C = AT0MIC(<7 C r). We first prove, by induction on the structure of a C r, that 
ChaCr and that C is atomic. 

If cr C r is atomic, then, trivially, C h <r C r and C is atomic. 

If cr is of the form a = CTi— x72 an d r is °f the form r = ri->r 2 , then we can assume 
inductively that ATOMIC^ C <n) h tj C ffl and ATOMIC((T 2 C r 2 ) h <r 2 C r 2 . Thus, 
C I- T\ C cti and C h cr 2 C r 2 , and so, by rule (arrow), C \~ a C r. To show that C is 
atomic, we can assume inductively that both ATOMIC(n C o\) and ATOMIC(cr 2 C r 2 ) 
are atomic; thus, so is C. 

If a is of the form a — (h,Z) and r is of the form r = (h',Z'), where h and h! are 
non-empty, then, since a C r is matching, dom(h) = dom(h'). Since dom(h) ^ <j>, we can 
assume inductively that 



and that 
Thus, 



AT0MIC((4>, Z) C (&£')) h (<f>,Z) C (0,Z') 

for all / e dom(/i), ATOMIC(/i(/) C />'(/)) I" KO C /*'(/). 
C h <cA,Z) C (0,2') and V/ G dom(h). C \- h{l) C //(/). 



Therefore, by rule (record), C \- a C t. To show that C is atomic, we can assume induc- 
tively that ATOMIC((<j), Z) C (<f>,Z')) is atomic, and that V/ G dom(h), ATOMIC(/i(/) C 
h'(l)) is atomic. Therefore, so is C. 

Since a C r is matching, one of the above cases must hold, thus proving the first part 
of the lemma. 

To show that this set is minimal, we again proceed by induction on the structure of 
subtype assertions. We wish to prove that, for any atomic set C", if C" h a C r, then 
C h ATOMICO C r). 

If cr C r is atomic and C" h cr C r, then C" h ATOMIC(cr C r) trivially. 

If a C r is of the form c»i— >er 2 ^ rx— »r 2 , then, by Lemma 3.5.2, C" h Ti C cti and 
C" r- <r 2 C r 2 . We can thus assume inductively that C" h ATOMIC (ri C a{) and C" h 
ATOMIC(cr 2 C r 2 ). Therefore, C" h C. 

If <7 is of the form a — (h,Z) and r is of the form r = (h',2 1 ), where h and /i' are 
non-empty, then, by Lemma 3.5.3, dom(h) = dom(h') / ^ C" I- (<I>,Z) C (<fi,Z') : and 
V/ G dom(h). C \- h(l) C /i'(/). Since dom(h) ^ c6, we can assume inductively that 

C" I- ATOMIC((^>,Z) C (&.Z')) and V/ G (fom(ft). C" h ATOMIC(/i(7) C /i'(/)). 

Thus, C" h C. 

Since cr C r is matching, one of the above cases must hold, thus proving the lemma. ■ 
Before proceeding to develop our notion of instance, we need some definitions. We 
say that a substitution S is a matching substitution for a set C of possibly nonmatching 
assertions T\ C r 2 if SC is defined and every St\ C 5r 2 G SC is matching. Furthermore, 
we say that a substitution S respects a set C of atomic subtype assertions T\ C r 2 if SC is 
defined and every St\ C ,5Y 2 G 5C is matching. 
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Using the results of Lemma 3.5.4, we now define 

S • C = (J ATOMIC(Sct C St) 

crCreC 

for any S that respects an atomic set C. The following lemma states that this definition of 
• gives us precisely the desired behavior. 

Lemma 3.5.5 If a substitution S respects an atomic set C, then there is an atomic set 
S • C with S • C t- SC and such that if C is any set of atomic subtype assertions with 
C h SC, then C'\- S»C. 

Proof. Let 5 • C = UtCtgC AT0MIC(5ct C St). The proof of the lemma follows 
easily by Lemma 3.5.4. 

Since S respects C, we know that V<r C r e C. So matches St. Then, by Lemma 
3.5.4, we know that V<r C r e C. AT0MIC(S<7 C St) is atomic and that Ma C r € 
C. AT0MIC(5(J C St) h So C St. Thus, S • C is atomic. Moreover, since SC = 
UacASa C 5r), 

|J AT0MIC(6'a C 5r) h 6*C 

(tCt€C 

proving the first part of the lemma. 

To prove the second part of the lemma, we note C h SC implies that V<7 C r £ C. C h 
Sct C 5r. By Lemma 3.5.4, we know that Va C r € C, C" h ATOMIC(Sct C Sr). Thus, 

Ch (J ATOMIC(SV C 5r), 

aCr£C 

which proves the lemma. ■ 

We note that, in our original definition of instance, if C h SC then, by Lemma 3.5.1, 
S must respect C. Thus, putting it all together, we say that 

Definition 3.5.6 A typing C',A' D M:a' is an instance of the typing C,Ad M:a by a 
substitution S if S respects C, is defined on A and a, and 

C h 5 • C, A' D SA, and a' = Sa 

We often simply say one statement is an instance of another, without mentioning the 
substitution involved. 

We wish to prove ultimately that, for any typable expression M, our type inference 
algorithm infers a "most general" typing; that is, a provable typing for M whose set of 
instances is exactly the set of provable typings for M. To this end, we would like to follow 
[Mit84] and show that every instance of a provable typing is provable. Then, simply showing 
that the typing inferred by the algorithm is provable would give the proof of one direction. 
However, it turns out that the partiality of substitution complicates the situation. 

Since a derivation of a typing C,A D M: a may involve type expressions that do not 
appear explicitly in this statement, a substitution which is defined on C, A D M: a may not 
be defined on all typings used in its proof. To see why this is a problem, consider the typing 

0, v: {X} D (fn {a = x; u) =► {u}){a = 3; v} : {X} 
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which follows from the typing 

0, v. {X} D fn {a = x; u) => {u} : {a: int; X}^{X} 

by rule app. For the sake of simplicity, we do not consider the set of subtype assertions, 
since they are not relevant to this discussion. The typing statement for the first term 
is syntactically well- formed if we substitute any record type for X. However, the second 
typing, which is needed to prove the first, becomes ill-formed if we replace X by a: bool; y, 
say, since this gives a two types. Thus, for the expression (fn {a = x;u} => {u}){a — 
3; v} : {X}, there is a instance of a provable typing that is NOT provable. It is easy to 
show by contradiction that this implies that no most general typing exists for the above 
expression. 

This example illustrates the fact that in order to have every instance of a provable typing 
be provable, we must impose additional conditions on substitutions. Specifically, we must 
keep track of type expressions that appear in the derivations, but not in the final typing 
statement. 

Fortunately, the required bookkeeping is not as complicated as it might appear at first 
glance. A careful analysis of the typing rules reveals that for all but one rule, any sub- 
stitution defined on the consequent of the rule (the typing statement below the horizontal 
line) will necessarily be defined on all assertions in the antecedent. For rule coerce, this is 
a consequence of the following lemma. 

Lemma 3.5.7 Suppose that a substitution S respects an atomic set C , and C h o C r or 
C\-t C a. 

1. If S is defined on a, then S is defined on r. 

2. If S is defined on a and r, then So matches St. 

Proof. We note that by Lemma 3.5.1, o and r must match. We also note that, for 
any S and Z, S((f>,Z) is always defined. We prove the lemma by induction on the length 
of the derivation of o C r or r C o from C. 

If the derivation of a C r from C requires no steps, then o C r is of the form t\ Cl 2 , 
c Q t, t C c, c\ C C2, or (4>,Z) C ($, Z'). To prove (1), we note that the application of 
5 to a type variable, ground type, or a record type whose first component is the empty 
function is always defined. To prove (2), we note that since the derivation requires no steps, 
o C t £ C. Since S respects C, So matches St trivially. The proof of (1) and (2) for the 
case where C h r C o is analogous. 

If the final step of the derivation of a C r is (trans), then, C \- o C. t must have followed 
by the antecedents o C 7 and 7 C r for some 7. To prove (1), we note that since the proof 
of o C 7 is shorter than that of o C r, we can assume inductively that S is defined on 7. 
Then, since the proof of 7 C r is also shorter than that of a C r, we can assume that S 
is defined on r. To prove (2), we note that since the proof of o C 7 is shorter than that 
of <r C r, we can assume inductively by (1) that S is defined on 7. We can then assume 
inductively by (2) that So matches 67, and that 57 matches St. Therefore, by transitivity, 
So matches St. The proof of (1) and (2) for the case where C h r C o is analogous. 

If the final step of the derivation of o C r is (arrow), then o must be of the form 
o = o\— >02 and r must be of the form r = t\— >t 2 , and C \~ o C t must have followed by 
the antecedents T\ C o\ and o<i C t 2 . Since, by assumption, So is defined, so are So\ and 
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Sa 2 . Since the proofs of t\ C <ti and a 2 C t 2 are shorter that that of a C r, we can assume 
that St\ and St 2 are defined and that St\ matches So\ and Sa 2 matches St 2 . Thus, r 
is defined, and Sa matches St, proving (1) and (2). The proof of (1) and (2) for the case 
where C r- r C a is analogous. 

If the final step of the derivation of a C r is (record), then a must be of the form 
a = (h,Z) and r must be of the form r = (h',Z'), where dom(h) = dom(h') ^ </>. Also, 
C \- a C r must have followed by the antecedents (<f>, Z) C (0, Z') and VZ G dom(h). h(l) C 
/V(Z). 

To prove (1), it suffices to show that VZ G dom(h'). S(h'(l)) is defined and that dom{h')n 
dom(left(S(4>,Z'))) = cj>. Since, by assumption, Sa is defined, then 

dom(h) fl dom(left(S(4>, Z))) = <f>, 

and VZ G dom(h). S(h(l)) is defined. Since, for all Z G dom(h), the proofs of Zi(Z) C Zi'(Z) are 
shorter than that of a C r, we can assume inductively that VZ G dom(h). S(h'(l)) is defined. 
Since the proof of (cf>, Z) C (0, 2') is shorter than that of cr C r, we can assume inductively 
by (2) that S{(j),Z) matches S(<fr,Z'). Thus, 

dom(left(S{4>, Z))) = dom(left(S(<f>, Z'))), 

which proves (1). 

To prove (2), we note that we can assume inductively that for all Z G dom(h), S(h(l)) 
matches S(h'(l)), and that S(<f), Z) matches S(<j>, Z'). Therefore, if we let h\ = left(S(<f>, Z)) 
and h 2 = left(S(4>,Z'}), then by the definition of match, dom(h\) = dom(h 2 ), and VZ G 
dom(hi). Zii(Z) matches h 2 (l). Careful inspection of the definition of match shows that 
this implies that Sa matches St, as desired. The proof of (1) and (2) for the case where 
C \- t C a is analogous, which proves the lemma. ■ 

In most other typing rules, every type expression appearing in the antecedent occurs 
(possibly as a subexpression) somewhere in the consequent. The only exception is in the 
application rule app, where the so-called cut formula (a, as the rule is written) is eliminated. 
(This will come as no surprise to proof theorists.) Thus, in order to determine which 
substitutions preserve provability of typing statements, we only need to keep track of the 
cut formulas used in proofs. 

Since the set of cut formulas will be used as a restriction on allowable substitutions, we 
adopt a notation that combines typing statements with restrictions. We will call a formula 
R | C, A D M: a combining a typing statement with a set R of type expressions a restricted 
typing statement. Moreover, we say that 

Definition 3.5.8 C, A D M:a is R -provable if C,A D M:a is provable by a derivation 
using only types from R as cut formulas, and we write h R \ C, A D M: a. 

Notice that since there are no function applications (and therefore no cut formulas) 
in patterns, there is no need to compute any restriction on substitutions for patterns - 
every well-formed substitution instance of a provable pattern typing is provable. However, 
due to the algorithmic advantages that arise from the similarities between patterns and 
expressions, we use restricted typing statements for patterns as well, noting here that R 
will always be empty. 

Using restrictions, we may now define a useful instance relation on restricted typing 
statements. 
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Definition 3.5.9 A restricted typing R' \ C , A' D M: a' is an instance of R\C,A D M:a 
by substitution S if S respects C, is defined on R, A, and a, and 

R' D SR, C'V S • C, A' 2 SA, and a' = Sa 

Again, we often simply say one restricted typing statement is an instance of another, 
without mentioning the substitution involved. 

While we have defined "provability" of a restricted typing statement R\C,A D M:a 
using the typing system for statements without restrictions, the typing system of Section 
3.4 can be reformulated to prove restricted statements directly. The changes are relatively 
minor. Essentially, restrictions are added to each statement in each rule, with the cut type 
(formula) added to the restriction set in the consequent of rule app. It is easy to show that 
a restricted statement is provable in this augmented system iff it is improvable. Through 
the rest of the paper, we refer to this augmented system, which is summarized in Table 3.1, 
as the iZ-typing system. 

3.6 Properties of the R- Typing System 

This section is devoted to proving Theorem 3.6.7, the main theorem of this chapter, which 
shows that, in iZ-typing system, all instances of a provable typing are provable. In order to 
prove this theorem, we will need to use a number of technical properties of the i2-typing 
system. Thus, before presenting the proof of Theorem 3.6.7, we first discuss these technical 
properties in some detail. 

First, we want to show that, if a restricted typing R | C, A D M: a is provable, then if we 
add "extra" type restrictions to R, "extra" subtype assertions to C, or "extra" variable-to- 
type or extension variable-to-record type associations to A, the resulting restricted typing is 
also provable. As a consequence of these properties, we can prove Theorem 3.6.7 by simply 
showing that h R | C, A D M: a implies that h SR \ S • C, SA D M: So for any substitution 
S that respects C and is defined on R, A, and o. 

The following three lemmas formally state the properties mentioned above. 

Lemma 3.6.1 If h R\ C, A D M: a and R' D R, then h R'\C,AD M:o. 

Proof. We prove this lemma by induction on the length of the derivation of h 
R\C,AD M:a. 

If the derivation requires no steps, then h R \ C, A D M:a follows from either (int), 
(real), (bool), (string), (var), (reel), (rec2), or (const). The lemma holds trivially since, 
for any R', h R' | C, A D M: a. 

If the final step of the derivation is (coerce), then h R \ C, A D M: a must have followed 
by the antecedents h R \ C, A D M: 7 and C h 7 C a for some 7. Since the proof of this 
is shorter, we can assume inductively that h R! \ C, A D M:~{. By (coerce), we have that 
\- R'\C,AD M:a. 

If the final step of the derivation is (app), then M is of the form M = M'N'. Thus, 
for some 7, R = R-i U {7}, and h R \ C, A D M:a must have followed by the antecedents 
h R\ I C, A D M'\ 7— ><7 and \~ Ri\C, A D N': 7. Since the proofs of these are shorter, and 
since R' D Ri, we can assume that h R'\C,A D M'\ 7— >-o- and h R' \ C, A D N': 7. Since 
7 G R' , we can infer that h R' \ C, A D M: a by (app). 

If the final step of the derivation is (abs), then M is of the form M — f n P =$■ M' and a is 
of the form er = o\— >a 2 . Moreover, h R \ C, A D M: a must have followed by the antecedents 
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int R\C,ADb: int whenever b is an integer 

real R\C,ADb: real whenever b is a real 

600/ R I C, A D b: bool whenever & is a boolean 

string R \ C, A D b: string whenever b is a string 

const R\C,ADq: Sr q whenever S is defined on T q , where r q is the built-in type for q 

var R I C, A D x:a whenever x: a € A 

app 

abs J " ' ^ n y^ j' _^ j"'r>""V ^ ^ l _ J "V" ■uars(A') = vars(P) 

coerce „ . „ , 

J2|C,yl D Af:r 

reci R\ C, A D (<J>, EMPTY): (<f>, NULL) 

rec2 R \ C, A D (</>, u): (h, Z) whenever u: (h, Z) G A 

R\C,Ap(<j>,E): {h 2 , Z), V/ £ dom(/). iZ | C, A D /(/): /n(Z) 

rec <? 5 ' ' ' — . , „. ,, , — —. -. — — all typings well-forme 

R\C,AD (f,E): (ht + ht^) ™ 5 

where dom(f) = dom(hi) ^ <f> 
Table 3.1: The .R-Typing System 



R | C, A D M: a -+ 


t, R\C,AD N:a 


Rll{a}\C,AD MN:r 


R\C op ,A' D P:a, 


R\C,A[A'] D M:t 


R\C,ADfnP 


' =J> M : a ->■ r 


R\C,AD M: 


a, C\~ a Ct 
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h R | C° p , A' D P: o x and h R \ C, A[A'] D M'\ a 2 for some A' such that vars(A') = vars(P). 
Since the proofs of these are shorter, we can assume that (- R'\C op ,A' D P:o\ and h 
R' | C, A[A'] D M': a 2 . By (abs), we have that h R' \ C, A D M: a. 

If the final step of the derivation is (rec3), then M is the form M = {f,E) and a 
is of the form a - (hi + h 2 ,Z). Moreover, h iE|C,A D M: cr must have followed by 
the antecedents dom(f) = dom(hi) ^ <f>, \- R\C,A D (<f>,E): (h 2 ,Z), and V7 € dom(j). h 
-R | C, ^4 D /(/): h\(l). Since the proofs of these are shorter, we can assume that \- R' \C,A D 
(<f>,E):(h 2 ,Z), and that V/ 6 dom(f). h iZ'ICA D f{l):hi(l). By (VecS,), we can infer 
thath i?' | C, A D M: a, which proves the lemma. ■ 

Lemma 3.6.2 If h R\Ci,A D M:a and C 2 h Ci, w/iere C2 is an atomic set, then h 
R\C 2 ,A D M:a. 

Proof. We prove this lemma by induction on the length of the derivation of I- 
R\C U AD M:a. 

If the derivation requires no steps, then h R\Ci,A D M:a follows from either (int), 
(real), (bool), (string), (var), (reel), (rec2), or (const). The lemma holds trivially since, 
for any C 2 , h R \ C 2 , Ad M:a. 

If the final step of the derivation is (coerce), then, h R \ C\, A D M: a must have followed 
by the antecedents h R\Ci,A D M:j and Ci h 7 C a for some 7. Since the proof of 
h R\Ci,A D Mif is shorter, we can assume inductively that I- R\C 2 ,A D M:-y. Since 
C 2 \~ C\, we know that C 2 h 7 C a. By (coerce), we have that h i2 | C2, A D M: a. 

If the final step of the derivation is (app), then M is of the form M = M'N', and 
h -R|Ci,A D M:<7 must have followed by the antecedents H jR|Ci,A D M':~f— >cr and 
h .R| Ci,y4 D JV':7 for some 7. Since the proofs of these restricted typing statements are 
shorter, we can assume that h R \ C 2 , A D M': *y^-a and h R | C 2 , A D TV': 7. By (app), we 
have that h ^ | C 2 , A D M:a. 

If the final step of the derivation is (abs), then M is of the form M = f n P =>■ M' 
and ct is of the form <r = <7i^^<T2. Moreover, h R\Ci,A D M: <j must have followed by 
the antecedents h R\Ci° v ,A' D P:ai and I- i?|Ci,A[A'] D M':a 2 for some A' such that 
t;ar,s(A') = vars(P). Since the proofs of these restricted typing statements are shorter, we 
can assume that \- R \ C 2 ° P ,A' D P: o\ and h R \ C 2 , A[A'] D M'\ a 2 . By (abs), we can infer 
that h R\C 2 ,A D M:a. 

If the final step of the derivation is (rec3), then M is the form M — (f,E) and a is 
of the form a — (hi + h 2 ,Z). Moreover, f- R\Ci,A D M: a must have followed by the 
antecedents dom(f) = dom(hi) ^ <f>, \- _R|Ci,^4 D (<f>, E): (h 2 ,Z), and V7 G dom(f). h 
R I C\, A D /(/): hi(X). Since the proofs of these restricted typing statements are shorter, we 
can assume that h R \ C 2 , A D (4>, E): (h 2 , Z), and that 

V/ e dom(f). \- R\C 2 ,AD /(/): h^l). 

Thus, by (recS), h R\C 2 ,A D M: a. m 

We prove a slightly more complicated lemma for type environments. In our proof of 

Theorem 3.6.7, we only need to use the second property outlined below; however, in the 

proofs of our main theorems in Chapter 4, we will need to use all three of the these properties. 

Lemma 3.6.3 Suppose that h R | C, A D M: a . 

1. If w occurs free in M, then w.t G A for some t. 
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2. If w.t 6 B for every w:t € A with w free in M , then h R\C,B D M: a. 

3. There is a proof of\- R\C,B D M:a that is of the same length as that of\- R\C,AZ) 
M:a. 

Proof. We note that proving part (1) is equivalent to proving that if h- R \ C, A D M: a, 
then vars(M) C vars(A). For part (2), it is sufficient to prove that if h R | C, A D M: a 
and if Am Q B, where Am = {w: a \ w:a £ A and w 6 vars(M)} then h R | C, B D M: a. 
We prove the lemma by induction on the length of the derivation of h R | C, A D M: a. 

If the derivation requires no steps, then the axiom used is either (int), (real), (bool), 
(string), (var), (reel), (rec2), or (const). Since vars{b) = var s{{4>, EMPTY)) = vars(q) = 
</>, part (1) is trivially true for all the cases other than (var) and (rec2). To prove (1), 
we note that if the rule applied is (var) or (rec2), then vars(M) C vars(A) by the axiom 
itself. Similarly, part (2) is trivially true if the rule applied is any other than (var) or 
(rec2), since t- R\C,B D M: a for any B. To prove (2), we note that if the axiom used 
is (var), where M = x, then Am — {x:cr}. Since, by assumption, Am ^ B, we can 
infer that I- R\C,B D M: o by (var). If the axiom used is (rec2), where M — (<f>,u), 
then Am — {u:o}. Since, by assumption, Am C B, we can infer that h R\C, B D M:a 
by (rec2). For part (3), we note that h R\C,B D M:a holds by the same axiom as 
h R\C,AD M:a. 

If the final step of the derivation is (coerce), then h R \ C, A D M: a must have followed 
by the antecedents h R\C, A D M:~f and C h 7 C a for some 7. Since the proof of 
h R I C, A D M: 7 is shorter, we can assume inductively that (1) holds true for M. To prove 
(2), we can assume inductively that h R\C, B D M:j. Since C H 7 C a, we can derive 
by rule (coerce) that \- R \ C, B D M: a. To prove (3), we can assume inductively that the 
proof of h R I C, B D M: 7 is of the same length as that of h R \ C, A D M: 7. By (coerce), 
we can infer that (3) holds for h R \ C, B D M: a. 

If the final step of the derivation is (app), then M is of the form M = M'N', and 
h R\C, A D M:a must have followed by the antecedents h R \ C, A D M'-.j—ta and (- 
R I C, A D N': 7 for some 7. Since the derivations of these are shorter, we can assume that 

vars(M') C vars(A) and vars(N') C vars(A). 

Thus, vars(M) C vars(A). To prove (2), we note that Am Q B implies that Am> Q B and 
An> C B. We can thus assume inductively that h R\C,B D M'-.j^a and h R\C, B D 
TV': 7. By rule (app), we can infer that h R\C,B D M:a. To prove (3), we can assume 
inductively that (3) holds for h R \ C, B D M':-f->a and for \- R | C, B D N':-y. By rule 
(app), we have that (3) holds for h R \ C, B D M: a. 

If the final step of the derivation is (abs), then M is of the form M = f n P => M' 
and a is of the form a = o~\-+02- Moreover, I- R\C, A D M:a must have followed by 
the antecedents h R\C° P ,A' D P:o x and h R \ C, A[A'} D M':a 2 for some A' such that 
vars(A') = vars(P). Thus, we can assume inductively that vars(M') C vars(A[A']). We 
note that by definition, A[A'] — Ai U A', 

where A — A\ U A2, A2 = {w: a \ w: a G A and w £ vars(A')}, 

which implies that A[A'] - A' = A\. Therefore, 

vars(M') — vars(P) C vars(Ai) C vars(A), 
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as desired. To prove (2), we note that A M Q B implies that (A[A']) M Q B[A'], and 
thus we can assume inductively that h R\C,B[A'] D M':a 2 . By (abs), we can infer 
that h R\C, B D M:a. To prove (3), we can assume inductively that (3) holds for h 
R | C, B[A'} D M'\ a 2 . By (abs), we have that (3) holds for h R | C, B D M: a. 

If the final step of the derivation is (rec3), then M is the form M = (f,E) and a is 
of the form a = \h\ + h 2 ,Z). Moreover, 1- R\C,A D M:a must have followed by the 
antecedents dom(f) - dom(fti) ^ <f>, h R\C,A D (<f>,E): (h 2 , Z), and VZ G dom(f). h 
-R | C, A D /(0 : ^i(0- We can assume inductively that 

vars({<f>, E)) C wars(A) and that V7 G dom(h). vars(f(l)) C ?;ar,s(A). 

Thus, vars(M) C var-s(A), proving (1). To prove (2), we note that Am Q B implies 
that A^e) C B and that V/ G dom(h). Aj^ C i?. We can thus assume inductively that 
\- R\C,B D (<f>,E):(h 2 ,Z), and that 

VZ e dom(/). I- i? | C, B D /(/): ^(Z). 

By rule (rec3), we can infer that (- if! | C, £ D M: a. To prove (3), we can assume inductively 
that (3) holds for h R \ C, B D <<£, E): (h 2 , Z) and for VZ e dom(f). \- R\C,B D /(/): fci(/). 
By (rec3), we have that (3) holds for h if! | C, 5 D M: ct, proving the lemma. ■ 

The next three lemmas present some properties about substitutions that we will need 
in the proof of Theorem 3.6.7 for technical reasons. 

Lemma 3.6.4 Suppose that a, 7, andr match. IfC is an atomic set, andC h ATOMIC(ct C 
7) and C h AT0MIC(7 C t), then C h ATOMIC(a C r). 

Proof. The proof proceeds by induction on the structure of a, 7, and r. If a C 7 and 
7 C t are atomic, then ATOMICO C 7) = {a C 7}, and AT0MIC(7 C r) = {7 C r}. 
Thus, C h {a C r}, as desired. 

For the remaining cases, the proof follows by simple induction. ■ 

Using the above lemma, we show the following property. 

Lemma 3.6.5 Suppose that a substitution S respects an atomic set C and is defined on a 
and t. IfC\-o-Cr, then S • C h ATOMIC(Sct C St). 

Proof. We prove the lemma by induction on the length of the derivation of a C r 
from C . 

If the derivation of a C r from C requires no steps, then a C r £ C. Thus, by definition, 

AT0MIC(S<7 C St) e S • C. 

If the final step of the derivation of o C r is (trans), then C h a C r must have followed 
by the antecedents a C 7 and 7 C r for some 7. By Lemma 3.5.7, we have that S is defined 
on 7. Since the proofs of a C 7 and 7 C r are shorter than that of a C r, we can assume 
that 

S •C\~ ATOMIC(.SVt C 57) and that S • C \~ ATOMIC^ C St.) 

By Lemma 3.6.4, we can infer that AT0MIC(5 • C h Sa C SY). 

If the final step of the derivation of it C t is (arrow), then a must be of the form 
a — o\^o- 2 and r must be of the form r = ri— >T2, and C \- a C t must have followed by 
the antecedents T\ C cti and (T2 C T2- Since, by assumption, So- and St are defined, so are 
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Sai, Sa 2 , Sr-i, and St 2 . Since the proofs of T\ C <7i and a 2 C r 2 are shorter that that of 
o C r, we can assume that 

5.Ch ATOMIC(Sri C Sa x ) and 5 • C h ATOMIC(S*ct 2 C 5r 2 ). 

Thus, 5 • C h ATOMIC(SV C SY). 

If the final step of the derivation of a C r is (record), then a must be of the form 
a = {/i, Z) and r must be of the form r = (h',Z'), where dom(h) = dom(h') ^ 0. Since the 
final step of the derivation is (record), we can assume that C \- a C. t must have followed 
by the antecedents (4>, Z) C (0, 2') and V7 G dom(h). h(l) C Zi'(Z). Since the proofs of these 
inclusions are shorter, we can assume inductively that 

VZ 6 dom(h). S»C\- ATOMIC(S(h(l)) C S(h'(l))) 

and 

5 • C h AT0MIC(5{^>, 2} C £{0, 2')) 

Let (h s ,Z s ) = S{4>,Z), and let {h 3 ',Z s ') = S(<f>,Z'). Since 6V and St match, we can infer 
that dom{h s ) = dom(h s '). Then, 

V/ e dom(h s ). S • C h ATOMIC(/i s (Z) C /i/(/)), 

and S • C h ATOMIC({0, Z,> C (0, Z/)). Thus, S • C h AT0MIC(5ct C 5*r). ■ 

The third property is as follows. 

Lemma 3.6.6 Suppose that (- R\C, A D P:a where vars(A) = vars(P). If S is a substitu- 
tion that respects C and is defined on o, then S is defined on A. 

Proof. The proof is by induction on the length of the derivation of f- R \ C, A D P: a. 
We write Ap for the type environment A restricted to the free variables of P; more precisely, 
Ap — {w. a | w: a 6 A and w £ vars(P)}. 

If the derivation requires no steps, then h R\C,A D P:a follows from either (int), 
(real), (boot), (string), (var), (reel), or (rec2). For all of the cases except (var) and (rec2), 
the lemma holds trivially since A = <f>. If the axiom used is (var), where P is of the form 
P = x, then A = {x:a}, and so, by assumption, S is defined on A. If the axiom used is 
(rec2), where P is of the form P = ((f), u) then A = {u: a}, and again by assumption, S is 
defined on A. 

If the final step of the derivation is (coerce), then h R | C, A D P: a must have followed 
by the antecedents h R | C, A D P:j and C h 7 C a for some 7. By Lemma 3.5.7, S is 
defined on 7. Since the proof of h R \ C, A D P: 7 is shorter that that of h R \ C, A D P: a, 
we can assume inductively that S is defined on A. 

If the final step of the derivation is (rec3), then P is the form P = (/, E) and a is of the 
form a = (hi + h 2 ,Z). Moreover, I- R \ C, A D P: a must have followed by the antecedents 
dom(f) = domihi) £ <f>, h R\C,A D (<j>,E):(h 2 ,Z), and VZ e dom(f). h- iE | C, A D 
/(Z): Zii(Z). By Lemma 3.6.3, we know that 

hi?|C,A< 0i£) D (<£,£} :(/*i,Z), 

and that 

VZ G <fom(/). h i? I C, A m D /(/): ^(/). 
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Moreover, by Lemma 3.6.3, we can infer that the proofs of these are shorter than that of 
h R\C,AD P:a. 

We can thus assume inductively that V7 £ dom(f). S is defined on Ajq) and that S is 
defined on A^^y Since 

A = U A /w U ^W>> 

ledom(f) 

S is defined on A, which proves the lemma. ■ 

Having developed all the necessary technical machinery, we now prove the main theorem 
of the chapter. This theorem shows that the il-typing system has the important property 
that the original typing system lacked: namely, that all instances of a provable typing are 
provable. In Chapter 4, we will make use of this property to show that the algorithm infers 
most general typings. 

Theorem 3.6.7 Suppose that R'\C',A' D M:a' is an instance of R\C,A D M:a. If 
\- R\C,AD M:tr, then h R' \ C, A' D M: a'. 

Proof. We prove the lemma by induction on the length of the derivation of h 
R\C,A D M:a. 

We note that if R! \ C, A' D M: a' is an instance of R \ C, A D M: a, then there exists a 
substitution S such that S respects C and is defined on R,A and a, and such that 

R' DSR, C h S • C, A' D SA, and a' = Sa. 

If the derivation requires no steps, then R | C, A D M: a must have followed by a typing 
axiom. For the purposes of our proof, it suffices to show that h SR \ S»C, SA D M: Sa, since 
we can then conclude by Lemma 3.6.3, Lemma 3.6.2, and Lemma 3.6.1 that h R' \ C, A' D 
M:a'. If the typing axiom used is (int), (real), (bool), (string), or (reel) then, trivially, 
I- SR | S • C, SA D M:Sa by that same axiom. If the axiom used is (var) or (rec2) 
\- SR | S • C, SA D M: Sa follows by that same axiom, since Sa G SA. 

Otherwise, the axiom used was (const). Thus, for some substitution T that is defined 
on T q , we have that a = Tr q , and so, Sa = S(TT g ). Since, by assumption, Sa is defined, we 
can assume that S(Tr q ) is defined as well. We would now like to show that Sa = (T; S)r q ; 
however, since T may map type or row variables other than T q to types, S; T may not 
be defined. We thus consider instead the substitution T' , where dom(T') — {r q }, and 
T'[r q ] = T[r q ], and note that since Sa is defined, so is S;T'. Thus, we can infer that 
h SR | S • C, SA D M: (5; T')a by (const). 

If the final step of the derivation is (coerce), then h R \ C, A D M: a must have followed 
by the antecedents h R \ C, A D M: 7 and C h 7 C a for some 7. We note that by Lemma 
3.5.7, S is defined on 7. Moreover, by Lemma 3.6.5, we have that S • C \- ATOMIC^ C 
Sa); thus, by transitivity, 

C h 5 7 C Sa. 

Since R' | C, A' D M: £7 is an instance of R \ C, A D M: 7, and the proof of h R \ C, A D 
M: 7 is shorter than that of h R \ C, A D M: a, we can assume that h R' \ C , A' D M: S*y. 
By (coerce), we can infer that h R' \ C , A' D M: a'. 

If the final step of the derivation is (app), then M is of the form M = M'N', and 
h R\C, A D M:a must have followed by the antecedents \- R± | C, A D M'-.-y-^a and 
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h R\ | C, A D N': 7 for some 7 and R such that R = Ri U {7}. Since by assumption S is 
defined on i£, we can assume that 

S is defined on 7. 

It is worthwhile to note here that this is precisely the reason that restriction sets are 
needed in our typing system. Without restriction sets, it is impossible to guarantee that 
S is defined on 7. 

Proceeding with the proof, we can now assume that R'\C',A' D M': S*y—>S(T is an 
instance of Ri | C, A D M': 7->ct and R' | C", A' D N': £7 is an instance of R x | C, A D N': 7. 
Since the proofs of H R y \ C, A D M':~/—>a and I- Ri | C, A D N':f are shorter than that 
of h R\C, A D M:a, we can assume inductively that h R'\C',A' D M':S*f->Scr and 
h R' I C", A' D N': £7. Thus, since £7 € R', we can infer by (app) that h #' | C, A' D M: a'. 

If the final step of the derivation is (abs), then M is of the form M = f n P =>■ M' 
and cr is of the form er = a\— >o~2. Moreover, h R | C, A D M:a must have followed by 
the antecedents h ^ | C op , Ap D P: a^ and \- R\C, A[Ap] D M'\ a 2 for some Ap such that 
vars(Ap) = vars(P). Since, by assumption, S is defined on a, we can assume that S is 
defined on a\ and <r 2 . Thus, by Lemma 3.6.6, 

S is defined on Ap. 

Since A[Ap] = A\ U Ap, where y^ C A, 

5 is defined on _A[Ap]. 

We can thus assume that SR \ S • C op , SAp D P: Sa\ is an instance of R \ C op , A P D P: o\, 
and that SR | S • C, £(A[Ap]) D Af' : £ct 2 is an instance of R \ C, A[A P ] D M'\ a 2 . Since 
the proofs of I- R\C° p ,Ap D P-.a^ and H R\C,A[Ap] D M'-.a^ are shorter than that 
of h E I C, A D M:a, we can assume inductively that h SR \ S • C op , SAp D P: Scri and 
h- SR\S»C, S(A[A P ]) D M': Sa 2 . By (abs), we can infer that h SR \ SC, SAD in P ^ 
M': So~i—*Sa2- Using the results of Lemma 3.6.3, Lemma 3.6.2, and Lemma 3.6.1, we can 
conclude that h R' \ C, A' D M: a'. 

If the final step of the derivation is (rec3), then M is the form M = (/, E) and a is of 
the form o = (h, Z), where, for some hi and h 2 , h — h\ + h 2 and dom(hi) D dom(h 2 ) = <f>. 
Moreover, h R \ C, A D M: a must have followed by the antecedents dom(f) = dom(hi) ^ 
<f>, \- R\C,A D (<J>,E):(h 2 ,Z), and V/ € dom(f). h R\C,A D /(ty.h^l). Since, by 
assumption, 5" is defined on a, we can assume that VZ G dom(h). S(h(l)) is defined and 
that dom(h) D dom(left(S(<f>,Z))) = <j>. Since h 2 C h, we can assume that S(h 2: Z) is 
defined as well. Thus, we can assume inductively that h R' \ C, A' D (<f>, E): S(h 2 , Z), and 
V/ G dom(f). h i?' I C", A' D /(/): S(hi(l)). It remains to show that the antecedents needed 
to derive h R! \ C, A' D {/, E): S(h, Z) by (rec3) are true. 

We first note that S(h 2 ,Z) = (h 2 ; S + left(S(<f>, Z)),right(S((f>,calgZ))}. Since + is 
associative, we have that 

S(h, Z) == <(/>! + h 2 ); S + left(S(4>, calgZ)), right{S{4>, Z))) 

which is equal to 

(hnS+ {h 2 - S + left(S(<j>, calgZ))), right(S(<f>, calgZ))). 

Thus, we can infer by (recS) that h R' | C, A' D (/, E): a', which proves the theorem. ■ 
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3.7 Most General Typings 

In this section, we discuss the notion of most general typings in the context of the iZ-typing 
system. We extend the definition of most general typings from [Mit84] a bit and say that a 
restricted typing R\C,AD M: a is a most general restricted typing for M iff the set of its 
instances is exactly the set of provable restricted typings for M. 

It is worth noting here that most general restricted typings in our system are essentially 
unique in the sense that that they form a natural equivalence class. This is also true of ML, 
where the equivalence relation is that all most general typings for a given expression are 
unique up to variable renaming. Interestingly, in ML, two typing statements are unique up 
to variable renaming iff they are instances of each other. With the introduction of subtyping 
assertions, however, the notions of instance and variable renaming are no longer equivalent, 
and it turns out that the correct equivalence relation for this system is that all most general 
restricted typings for a given expression are instances of one another. 

For example, 

4> I {s Q i), D fn x => x : s—>t 

and 

4> | {a C 6, c C d}, D f n x =>• x : c— >d 

are both most general restricted typings of the identity function, since every typing of 
fn x =>• x is an instance of both of them. These restricted typings are not unique up to 
variable renaming, but they are instances of one another. 

It is useful to point out here that the presence of an equivalence class of most general 
restricted typings versus a single most general restricted typing does not affect the decid- 
ability of the type inference problem. As we will prove in the next chapter, the algorithm, 
given a typable expression in the language, yields a most general typing for that expression. 
It does not matter which most general restricted typing is yielded, since it is possible to 
check whether one restricted typing is an instance of another. 

Lemma 3.7.1 For any restricted typing R \ C, A D M: a, the set of instances of R\C,A D 
M:a is recursive. 

We omit the proof here, stating only that the obvious algorithm takes time exponential 
in the size of the restricted typing. The difficulty in this algorithm seems to lie in checking 
the instance conditions on the R and C, and we haven't as yet had a chance to determine 
whether a polynomial time algorithm exists. We do know that if we assume that all ex- 
pressions in ML + are renamed {i.e., alpha-converted) so that all lambda-bound variables 
and extension variables in the expression are distinct, and we associate the corresponding 
expressions with the cut types in R, then checking the instance condition on this augmented 
set R can be done in polynomial time. It is unclear to us at the present time whether the 
condition on C can be checked in polynomial time; however, we haven't as yet had a chance 
to think about this issue in much detail. 

We note here that, as a consequence of Lemma 3.7.1, the decision problem for determin- 
ing whether a restricted typing for an expression M is provable is reducible to the problem 
of computing a most general typings for M. 
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3.8 Relating the R- Typing System to the Original System 

It may seem peculiar to the reader that we first developed a typing system that captured 
the form of subtyping discussed in Chapter 1, proceeded to discuss the technical difficulties 
in the typing system, and then modified the typing system so that it has the technical 
properties that we desire. The obvious question arises as to which typing system - the 
original typing system or the i?-typing system - is the "real" typing system that defines 
ML+? 

It turns out that the original typing system and the .R-typing system are, in fact, inti- 
mately related. More precisely, 

Lemma 3.8.1 A typing C,A D M:a is provable in the original typing system iff there 
exists a set R such that R | C, A D M: a is provable in the R-typing system. 

Proof. To prove one direction, suppose that \- C,A D M: a, and let R be the set of 
"cut" types in the derivation of C, A D M: a. Then there is a derivation of R \ C, A D M : a 
that uses the sequence of typing rules in the .R-typing system that correspond exactly to 
the sequence of typing rules used in the derivation of C, A D M: a. 

To prove the other direction, suppose that \- R\C, A D M:a for some set R. Then 
I - C, A D M: a by a derivation that uses the sequence of typing rules in the original typing 
system that correspond exactly to the sequence of typing rules used in the derivation of 
h R\C,AD M:a. m 

Furthermore, we can state the following property of the original typing system that is 
very similar to Theorem 3.6.7. 

Lemma 3.8.2 Suppose h C, A D M:a. IfC',A' D M:a' is an instance ofC,A D M:a by 
a substitution that is defined on the set of cut types in the derivation of C,A D M: a , then 
\-C',A' D M:a'. 

The proof is very similar to that of Theorem 3.6.7. 

Using this restricted notion of instance, we could formulate a definition of most general 
typings for the original typing system that "implicitly" referred to the set of cut types in the 
derivation, and proceed to show that the algorithm is "equivalent" to the original typing 
system. However, the .R-typing system provides a nice syntactic mechanism to explicitly 
keep track of these cut types, and therefore we will prove in Chapter 4 that the algorithm 
is "equivalent" to the iZ-typing system. However, using the above lemmas as justification, 
we consider the original typing system to be the typing system that defines ML + . 
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Chapter 4 

The Type Inference Algorithm 



4.1 Overview 

In this chapter, we present the type inference algorithm, GE, for ML + . We develop Theo- 
rems 4.5.3 and 4.6.4, the main theorems of this thesis, which show that, for every expression 
M of ML + , GE derives a most general restricted typing statement for M if M is typable in 
the i2-typing system of Chapter 3 and "fails" otherwise. More specifically, Theorem 4.5.3 
shows that GE is sound with respect to the i2-typing system; that is, for any expression 
M, if the algorithm succeeds with a restricted typing statement, then every instance of the 
typing is provable. Conversely, Theorem 4.6.4 shows that GE is complete with respect to 
the i?-typing system; that is, for any expression M, if there is a provable restricted typing 
for M, then the algorithm will succeed with a restricted typing statement of which the 
provable typing is an instance. 

This chapter is organized as follows. Sections 4.2 and 4.3 develop two algorithms, UNIFY 
and MATCH, respectively, that form the foundation of the type inference algorithm. The 
algorithm UNIFY for unification is used to combine most general restricted typings of 
subexpressions, while the algorithm MATCH for matching is used to guarantee that the 
set of subtype assertions in a most general restricted typing is atomic. The type inference 
algorithm, GE, is presented in Section 4.4, while Sections 4.5 and 4.6 prove that GE is 
sound and complete with respect to the i2-typing system. Finally, Section 4.7 relates the 
type inference algorithm to the original typing system. 

4.2 Unification 

As in ML, we will use unification to combine (restricted) typing statements about subex- 
pressions in the process of inferring a typing for an expression in ML + . The standard notion 
of unification is to produce a substitution that makes a pair of type expressions syntactically 
identical. However, because the first component of our record types is a function, we need 
to use a slightly modified definition of syntactic identity. To this end, we define syntactic 
likeness between type expressions as follows: 

• b\ is syntactically like 62 if &i and 62 are the same ground constant 

• q\ is syntactically like q? if q\ and qi are the same built-in constant 

• x is syntactically like x 
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• a— >t is syntactically like ct'— >t' if a is syntactically like a' and r is syntactically like 
t' 

• (h, Z) is syntactically like (h', Z) if dom(h) = dom(h') 
and V7 G dom(h). h(l) is syntactically like /i'(/) 

We say that a substitution S unifies a set 2? of equations between type expressions, or 
equivalently, that S is a unifying substitution for E, if, for all equations a = t G E, S is 
defined on <r and r, and 5<r is syntactically like St. 

In the process of computing most general typings for expressions in ML + , we would 
like to compute "most general unifiers" in order to combine the most general typings of 
subexpressions. Following [Rob65], we would like to define a substitution S that unifies a 
set E of equations between type expressions as a most general unifier for E if S unifies E 
and, for all substitutions T that unify E, there exists a substitution U such that S; U is 
defined and T = S; U. However, due to extended record types, it turns out that we will 
need to modify this definition somewhat. 

We illustrate the difficulty with the standard definition through an example. Consider 
the equation 

{a:int;X} = {b: bool; X'} 

Clearly, any substitution that unifies this equation must map X' to a record type that 
contains at least an a: int field and must map X to a record type that contains at least 
a b: bool field. Furthermore, the "rest" of X and X' must be identical. Thus, the most 
general substitution S that unifies this equation is 

S = [{b:bool;y}/X, {a: int; y}/X'], 

for some "fresh" y, where y is a row variable that does not occur anywhere in the set of 
equations that we are unifying. 

It turns out that the difficulty with the standard definition lies precisely in the intro- 
duction of such fresh row variables. Consider the substitution 

T=[{b: bool; NULL}/X, {a: int; NULL}/X', {a: real; NULL}/y] 

Clearly, T unifies the above equation. However, since any substitution U such that T — S;U 
must map y to {NULL}, the action of S; U on y differs from that of T. Therefore, there 
is no such substitution U, and thus, S cannot be the most general unifier for E. 

In order to overcome this difficulty, we introduce a "restricted" form of equality over 
substitutions. Let Q be a set of type variables and row variables. We say that S is equal 
to T with respect to Q, written S =q T, if V* G Q. St = Tt and VX £ Q. SX = TX. We 
also are more precise in our notion of "fresh" variables, and say that a row variable X is 
fresh with respect to Q if X G" Q. An analogous definition, which we will need in the next 
section, holds for type variables. 

Using these definitions, we restrict our notion of most general unifiers as follows. Let E 
be any set of equations between type equations, and let Q again be any set of type variables 
and row variables. We say that a substitution S is a most general unifying substitution for 
E with respect to Q if S unifies E and, for all substitutions T that unify E, there exists a 
substitution U such that S; U is defined and T =quq e S; U, where Qe is the set of type 
and row variables occurring in E. The idea behind this restriction is that, while computing 
S, we choose the "fresh" row variables to be fresh with respect to Q U Qe- If we ensure 
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that Q is a co-infinite set, then we will always be able to choose a "fresh" row variable, thus 
getting the behavior we desire. (Recall that we assume an infinite set of type variables and 
row variables in our system.) 

Using these ideas, our algorithm UNIFY takes a set of equations E between type ex- 
pressions and a co-infinite set Q of type variables and row variables and produces a most 
general unifying substitution for E with respect to Q U Qe, where Qe is the set of type 
variables and row variables that occur in E. If no unifying substitution for E exists, then 
UNIFY fails. UNIFY is a modification of Robinson's unification [Rob65], extended to solve 
equations between extended record types, and is quite similar to the unification algorithm 
described in [Wan87]. However, it corrects a bug in Wand's algorithm for unifying two 
extended record types; we postpone discussion of this bug to the proof of Lemma 4.2.1. 

Quite importantly, another subtle bug in Wand's algorithm is avoided by the syntactic 
restriction in ML + prohibiting duplicate field names within a record. Because the language 
of [Wan87] does not make this syntactic restriction, the algorithm given in [Wan87] for 
equations between row expressions is incorrect for his system; however, it is correct for our 
system. His corrected algorithm, which appears in [Wand88], needs to compute a set of 
most general unifiers, while our algorithm computes a single most general unifier. 

Lemma 4.2.1 Let E be a set of equations of the form a = r and let Q be a co-infinite set 
of type variables and row variables. Let Qe be the set of type variables and row variables 
that occur in E. There exists an algorithm UNIFY such that whenever there is a unifying 
substitution for E, UNIFY(E, Q) produces a most general unifying substitution with respect 
toQuQ E . Otherwise, UNIFY(E,Q) fails. 

The proof appears in the Appendix. 

4.3 Matching 

In the process of computing a most general restricted typing for an expression M, we 
will use unification to combine the most general restricted typings of the subexpressions 
of M. However, the most general unifier may not respect the sets of subtyping assertions 
in these typing statements, thus violating our requirement that typing statements contain 
only atomic subtype assertions. Therefore, we need to be able to compute a "most general 
matching substitution" for this set of possibly non-matching subtype assertions, so that we 
can apply the operation • developed in Chapter 3 to get a "most general" set of atomic 
subtype assertions. 

We would like to follow the standard notion of most general substitutions and say that a 
substitution S is a most general matching substitution for C if S is a matching substitution 
for C and, for all matching substitutions T for C, there exists a substitution U such that 
S; U is defined and T = S;U . However, a problem arises due to fresh type and row 
variables which is similar to the one of Section 4.2, and so we restrict our notion of "most 
general" in a similar manner. Let C be a set of possibly non-matching subtype assertions 
and let Q be a set of type variables and row variables. We say that a substitution 5 is a 
most general matching substitution for C with respect to Q if S is a matching substitution 
for C and, for all matching substitutions T for C, there exists a substitution U such that 
S; U is defined and T =quq c S; U, where Qc is the set of type and row variables occurring 
in C. Again, the idea behind this restriction is that the fresh type and row variables are 
chosen from the complement of Q U Qc ■ 
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An extremely useful property of matching is that the problem of finding a most gen- 
eral matching substitution for a set C of possibly non-matching subtype assertions can be 
reduced to the problem of finding a most general unifying substitution for a set E that 
is closely related to the set C. The basic idea here is that we treat the set C as a set of 
equations between types (rather than inequalities) and unify this set of equations. There 
is a minor complication, however, due to base types, since two distinct base types match 
but do not unify. In order to get around this difficulty, we replace all base types (and 
NULL) in C by special type variables (and row variable), and check that the most general 
unifier merely renames these special type variables and row variable. We then derive the 
most general matching substitution from this most general unifier S by "factoring" S into 
a "most general" substitution S\ composed with a "simple" substitution 5*2 such that all 
type variables and row variables occurring in the range of 5*1 are distinct and such that 52 
merely renames type variables and row variables. If we incorporate the set Q appropriately 
into the above procedures, we can use the properties of most general unifiers to show that 
the substitution Si is the most general matching substitution for C with respect to Q. 

Using these ideas, our algorithm MATCH takes a set C of possibly non-matching subtype 
assertions and a co-infinite set Q of type variables and row variables and produces a most 
general matching substitution for C with respect to Q U Qc, where Qc is the set of type 
variables and row variables occurring in C. If no matching substitution for C exists, then 
MATCH fails. Our algorithm is quite similar to the algorithm of [Mit84], extended to 
support base types and record types. 

This section is organized as follows. We will first show in more detail how the problem 
of finding matching substitutions reduces to the problem of finding unifying substitutions. 
Being careful about the set Q, we will then precisely define what it means for all type and 
row variables in the range of a substitution to be distinct, and then show how to "factor" 
any substitution S into two substitutions S\ and 5*2 with the properties outlined above. 
Finally, using these results, we will present the actual algorithm MATCH and give the 
proof of its correctness. 

In order to relate matching and unification, we first need to define precisely what it 
means for a substitution to merely rename type variables and row variables. Formally, we 
say that a substitution S is simple if, for all t G dom(S), there exists a type variable t' such 
that St — t' , and for all X 6 dom(S), there exists a row variable X' such that SX — ((f), X'). 
Similarly, a c-simple substitution corresponds to either renaming type variables and row 
variables or replacing them by base types or NULL, respectively. Formally, we say that a 
substitution S is c-simple if, for all t e dom(S), there exists either a type variable t' such 
that St = (' or a base type c such that St = c, and for all X g dom(S), either there exists 
a row variable X' such that SX = ((f), X') or SX = (<f>,NULL). It is easy to show that if 
T is a simple substitution or a c-simple substitution, then, for any substitution S, S;T is 
defined. 

Just to keep our definitions explicit, we formally define the range of any substitution S 
to be the set of type variables and row variables that occur in S[s] or S[y] for some s,y € 
dom(S). 

We now show precisely how the problem of finding a matching substitution for a set C 
(with respect to a set Q) reduces to the problem of finding a unifying substitution for a 
related set E (with respect to Q). 

Lemma 4.3.1 Let C be a set of subtype assertions a C t, where a and r may not necessar- 
ily match, and let Q be a finite set of type variables and row variables. Let Qc be the set of 
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type variables and row variables that occur in C, and let /,-„<, t rea i, ij 00 /, t string, and Xnull 
be fresh with respect to Q U Qc- Let C be the set C with all occurrences of int replaced 
with ti nt , all occurrences of real replaced with t rea [, all occurrences of bool replaced with 
tbool, all occurrences of string replaced with t str i n g and all occurrences of NULL replaced 
with Xnull- Let E = {a' = r' | o' C r' G C'}. 

T is a matching substitution for C iff there exist substitutions T\, T 2 , and T 3 , such that 
T<i is c-simple, T3 is simple, 

T =QuQ c Ti;T 2 , and Ti'; T 3 unifies E, 

where Ti' = T 1 \(QuQ c ), 

and, for all i G {int, real, bool, string}, 

1. (Ti';T 3 )i; ^ (t-+t, for any o~,t 

2. (Tj'jra)*,- + (h,Z), for any h,Z 

and (TV; T 3 )Xnull ± {h, Z), for any h ^ <f>. 

Proof. To prove one direction, suppose that T is a matching substitution for C. Let 
Qc - Qc U {i; I i G {int, real, bool, string}} U {X NULL }. Let s int , s TeaU s boo i, s string , 
and yNULL be fresh with respect to Q U Qc- 

Let T\ be a substitution whose domain is (Q U Qc)- Furthermore, T\ maps all type 
variables t in its domain to Tt with all occurrences of int replaced with s tnt , all occurrences 
of real replaced with s rea i, all occurrences of bool replaced with Sbooh all occurrences of 
string replaced with s str i ng and all occurrences of NULL replaced with y^ULL- (The action 
of T\ on row variables in its domain is analogous.) 

LetT 2 = [int/s,- n( , real/s rea /, bool/s(, oo; , string/s st „- n3 , {4>,NU LL)/y NU LL\- Clearly, 
T\\Ti is defined, and 

T =Que c Ti]T 2 . 

It is easy to see that Ti = Tif(QU Qc) = T a . Since T respects C and T 2 is c-simple, it 
follows that Ti respects C as well. 

Let T3 be the substitution whose domain is Q U Qc U range{T\) and such that T3 
maps all type variables in its domain to some type variable t' and maps all row variables 
in its domain to (</>, A"), for some row variable X' . Clearly, T 3 is simple, and so T^T^ is 
defined. Furthermore, since the i; and Xnull are fresh with respect to QuQc,we have 
that 2i*,- = U for all the «,-, and that T X X NULL = (4>,X NUL l)- Thus, (Ti;T 3 )£; = *' and 
{T\)T^)Xnull — (<f>,X'), satisfying conditions (1), (2) and (3) above. 

Since T\C is matching, we have that for all a C r G C, T\u and T\T differ only in the 
names of type variables and/or ground types and in the names on row variables and/or 
NULL. Thus, by the construction of Ti and C", we have that for all a' C t' G C", Ti<t' and 
Tir' differ only in the names of type variables and in the names of row variables. Thus, 
Ti;T 3 unifies E, proving one direction. 

To prove the converse, we note that T 3 is simple implies that for all a' C r' G C, T-i'a' 
matches T-yT 1 . Since Ty'ti = ti for all the i,-, and TxX NULL = (<f>, X NUL l), it follows that T\ 
is a matching substitution for C. Furthermore, by the definition of T\ and Qc, it follows 
that Ti is a matching substitution for C. 

Since T 2 is c-simple, Ti;T2 is also a matching substitution for C. Then, clearly, so is 
(Ti;T 2 )t(Q U Q c ), and thus so is T\(Q U Qc). By the definition of Q c , T is a matching 
substitution for C, proving the lemma. ■ 
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In order to show how to "factor" substitutions, we state precisely what it means for all 
the type and row variables occurring in the range of the most general unifier to be distinct. 
Since we do not want the these type and row variables to conflict with the set Q in our 
notion of most general matching substitutions, we incorporate Q into our definition. 

Definition 4.3.2 A substitution S chooses variables freely on a set Q of type variables and 
row variables if no type variable or row variable in Q occurs in range(S) and 

• For each t 6 Q, no type variable or row variable appears twice in St. 

• For each X £ Q, no type variable or row variable appears twice in SX. 

• For any distinct s,t € Q, no type variable or row variable in Ss appears in St. 

• For any distinct X,y € Q, no type variable or row variable in SX appears in Sy. 

• For any t, X £ Q, no type variable or row variable in St appears in SX. 

In the proof of correctness for the algorithm MATCH, we will need to use the prop- 
erty that choosing variables freely is preserved under composition of appropriately defined 
substitutions. 

Lemma 4.3.3 Suppose that a substitution S chooses variables freely on a set Q of type 
variables and row variables, and that a substitution T chooses variables freely on the set of 
all type variables and row variables occurring in all St or SX with t G Q, X € Q. If S;T 
is defined, then S;T chooses variables freely on Q. 

The proof is straightforward and we omit it. 

As alluded to previously, we will need to be able to "factor" a substitution S into 
a substitution Si that chooses variables freely on on a set Q of type and row variables 
composed with a simple substitution 52. To prove this property, we need to develop a 
linear ordering on the "components" of a type. First of all, we consider a record type (h, Z) 
to be written out as /i(/i), h(l 2 ), ...h(l n ), Z, where dom{h) = Ui<;<n an d the U are in 
lexicographic order. (The other types are written out in the expected manner.) Assuming 
this order, we can unambiguously refer to the m-th type variable occurring in a type, or 
similarly, the m-th row variable occurring in a type. Assuming that each occurrence of a 
type variable, row variable, base type, and NULL determines a "position" in a type, we can 
also unambiguously refer to the k-th position in a type. 

Lemma 4.3.4 Let Q} be a finite set of type variables and Q r be a finite set of row variables, 
and let Q — Q t U Q T . For any substitution S, there are substitutions Si and S 2 such that 
Si and 5*2 are computable, Si chooses variables freely on Q, S2 is simple, and S =q Si; 5*2- 

Proof. The proof is analogous to that of [Mit84]. To define Si and £2, let ij, t 2 , ... 
be an enumeration of Q* and let Xi, X 2 , ... be an enumeration of Q r , and let us partition 
the complement of Q} into disjoint sets Ui, U 2 , ... and partition the complement of Q r into 
disjoint sets >Vi, W 2 , .... It will be convenient to choose some enumeration of each Ui, say 
Mi = {<i,i, ti t 2, ■■■} and some enumeration of each Wj, say Wj = {<fj,i, Xj,2, ■•■}• 

For each t{ € Q*, let 5*1^' be the type expression derived by replacing the m-th type 
variable occurrence in Sti with the m-th type variable t 2 i, m from U 2 i and by replacing the 
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n-th row variable occurrence in Sti with the n-th row variable Xii, n from W 2 i- For each 
Xj G Q r , let S\Xj be the type expression derived by replacing the m-th type variable 
occurrence in SXj with the m-th type variable t 2 j+i, m from U 2 j+i and by replacing the 
7i-th row variable occurrence in SXj with the n-th row variable X 2 j + i, n from W 2j+ i. Let 
S 2 map i 2 i, m back to the m-th type variable in SU, t 2 j+i, m back to the m-th type variable 
in SXj, X 2 i, n back to the n-th type variable in SU, and X 2 j +1<n back to the n-th type 
variable in SXj. Clearly, S 2 is simple, and thus Si;S 2 is defined. It is easily verified that 
S\ chooses variables freely on Q and that S =q Si; S 2 . Moreover, all type expressions are 
of finite length, the complements of Q 1 and Q r do not need to be fully partitioned or fully 
enumerated. Thus, Si and 5*2 are computable by the procedure outlined above. ■ 

To show that the substitution that our MATCH algorithm computes is the most gen- 
eral matching substitution, we will need to use the fact that any substitution Si with the 
properties outlined above is "most general" in the following precise sense. 

Lemma 4.3.5 Let Q be a finite set of type variables and row variables. Furthermore, let S 
be any substitution, and let Si and S 2 be substitutions such that Si chooses variables freely 
on Q, S 2 is simple, and S =q Si; S 2 . If S =q Ti;T 2 for some simple substitution T 2 , then 
there exists a substitution W such that Si, W is defined and Ti —q Si; W. 

Proof. Since S 2 and T 2 are simple, it follows that, for any t e Q, the type expressions 
St, Sit, and Tit must match. Similarly, for any X € Q, the type expressions SX, SiX, and 
TiX must match. 

For any t 6 Q, consider the k-th position of Sit and the k-th position Tit. By the 
definition of "simple", it follows that either both positions contain type variables, both 
positions contain row variables, or both positions contain the same ground type. In the first 
case, since 5i chooses variables freely on Q, there is a well-defined substitution W mapping 
the type variable occurring in the k-th position of Sit to the type variable occurring in 
the k-th position of Tit. Similarly, in the second case, since Si chooses variables freely on 
Q, there is a well-defined substitution W mapping the row variable occurring in the k-th 
position of Sit to {(j>,y), where y is the row variable occurring in the k-th position of Tit. 
(An analogous statement holds for any X G Q.) 

Clearly, W is simple, and thus Si; W is defined. It is to verify that Ti =q Si; W , proving 
the lemma. ■ 

Having developed the necessary technical machinery, we now prove the main lemma 
of this section; namely, that there exists an algorithm MATCH that, given a set C of 
possibly non-matching subtype assertions and a set Q of type and row variables, computes 
a most general substitution for C with respect to Q. We also prove that the domain of 
MATCH(C, Q) is subset of Q U Qc, where Qc is the set of type variables and row variables 
that occur in C, since, for technical reasons, we will need to use this fact in our proof of 
completeness of GE in Section 4.6.4. 

Lemma 4.3.6 Let C be a set of subtype assertions a C r, where a and r may not neces- 
sarily match, and let Q be a finite set of type variables and row variables. Let Qc be the 
set of type variables and row variables that occur in C. There is an algorithm MATCH 
such that if there is a matching substitution for C, MATCH(C, Q) produces a most general 
matching substitution with respect to QU Qc- Otherwise, MATCH '(C, Q) fails. 

Furthermore, if MATCH (C, Q) succeeds, then dom(MATCH(C, Q)) C(QU Q c ). 

Proof. The algorithm is as follows: 
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MATCH(C, Q)= 

let Qc be the set of type variables and row variables that occur in C 

tint, treal, hod, t string, and Xnull be "fresh" with respect to Q U Qc 
C be the set C with 

all occurrences of int replaced with tint, 
all occurrences of real replaced with t rea i, 
all occurrences of bool replaced with hod , 
all occurrences of string replaced with t str ing, an d 
all occurrences of NULL replaced with Xnull 
E = {<t' = t'\o'Ct' € C'} 

Qc = Qc U {U | i € {int, real, bool, string}} U {Xnull} 
S = UNIFY(£,Qug c ,) 

if, for any ti such that i € {int, real, bool, string}, 
St{ = ct— >-r for any a, t or 
Sti = (h,Z) for any h,Z or 
S X NU LL - {h, Z) for any h ^ <f> 
then fail 
else let 5*i and 62 be the substitutions such that 

& — QuQ c i ^i' "^2 

and Si chooses variables freely on Q U Qc 

and S2 is simple 

S x ' = Si\(QU Qc) 
return S\ 



We first prove that if MATCH(C, Q) succeeds, then there is a matching substitution for 
C. More specifically, we show that MATCH(C, Q) produces a matching substitution for C. 
Suppose that MATCH(C, Q) succeeds. By Lemma 4.2.1, S is the most general unifier for 
E with respect to Q U Qc- Furthermore, S maps all the t{ to types that are not function 
types or record types and maps X^ULL to a record with (f> as its first component. Since E 
does not contain NULL or any base types and S is a most general unifier for E (w.r.t to 
Q U Qc), we have that for all a' = r' G E, both Sa' and St' do not contain NULL or any 
base types. 

Let S[' = Si \(QU Qc)- Since £2 is simple, and by the properties of S mentioned above, 
it follows that for all the /,-, there exists a type variable s t - such that S"ti — 5,-. Also, by the 
same reasoning, S'{Xnull — {<I>,X'), f° r some X'. Let 

^3 — [Sint/lint, ^real/^Teal, $bool j ^bool, ^string /^string , \*P, <* )/<*-NULL\ 

Since 5i chooses variables freely on Q U Qc, we have that 

Si ; £3 =quq c , S x 

Thus, since E contains only type and row variables from Qc, we have that Si'; S3; S2 unifies 
E. Noting that S3; S2 is simple, we can use Lemma 4.3.1 to prove that 5 is a matching 
substitution for C. Then, clearly, Si' must be a matching substitution for C. 

To prove the other direction, suppose that there is a matching substitution T for C. 
By Lemma 4.3.1, there exist substitutions Ti, T2, and T3 such that T =QuQ c 2~i;T2, T2 
is c-simple, T3 is simple, and such that Ti';T3 unifies E, where T\ = Ti\(Q U Qc)- By 
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Lemma 4.2.1, we can conclude that S = UNIFY(£, QuQ c >) succeeds, and that there exists 
a substitution U such that S; U is defined and such that S; U =quQ c , Ti'; T 3 . Furthermore, 
by Lemma 4.3.1, T/; T 3 maps all the ti to types that are not function types or record types 
and maps Xnull to a record with <f> as its first component. Thus, this property must also 
hold true for 5. By Lemma 4.3.4, it follows that 5*1 and S 2 exist and are computable; thus, 
MATCH(C, Q) succeeds. By the proof above, S\ is a matching substitution for C. 

It remains to show that there is a substitution W such that 6V; W is defined and 
T =quq c S X ';W. We first note that S =q u q c S 1 ';S 2 . We let S' = S\(Q U Q c ), and let 
U' = U\(QU Qc U range(S')). Since Qc Q Q c >, we have that Si'; S 2 ; U' is defined and 
that 

S; U =quq c Si ; S 2 ; U =quq c T\ ; T 3 

By Lemma 4.3.4, we can "factor" S 2 ; U' into U\\ U 2 such that 

S 2 ',U =Q U Q c Urange(Si') Ul',U 2 

and such that Ui chooses variables freely on Q U Qc U range(Si') and U 2 is simple. Since 
Si'; S 2 is defined and S 2 ; U' = ran ge(s 1 ') u ^'i u 2, it follows that Si'; U\ is defined as well. By 
Lemma 4.3.3, we have that 5i'; U\ chooses variables freely on Q U Qc- Moreover, 

£1 ; £2; U =quq c Si ; Ui; U 2 

By Lemma 4.3.5, there exists a simple substitution V such that 

Si'; U\;V =quq c T\ 

Thus, Si'; JJ\\ V =ql)Q c T\. Putting it all together, we have that 

Si ;Ui;V;T 2 —quQ c Ti;T 2 =quq c T 

Letting W = Ui;V;T 2 proves this direction of the lemma. 

To finish the proof of the lemma, we note that if MATCH(C, Q) succeeds, then, clearly, 
dom(Si') C (fiUQc). ■ 

4.4 The Type Inference Algorithm 

This section presents the type inference algorithm, GE, for ML + . GE is written in an 
applicative, pattern-matching style, and is defined by the mutually recursive clauses given 
in Table 4.1. 

The algorithms UNIFY and MATCH play a crucial role in GE, while a subsidiary role is 
played by algorithms for applying substitutions, composing substitutions, subtracting two 
type environments, computing the union of two type environments, and pasting two func- 
tions mapping labels to types. All of these subsidiary algorithms are assumed to fail when 
the desired result is not well-defined. For example, while we write Sa for the application of 
a substitution S to type expression cr, we assume in our algorithm GE that if the result is 
undefined (not a well-formed expression), then the entire algorithm will terminate in error. 
This notational convention makes the pseudo-code in Table 4.1 more readable. 
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GE(6) = | {c C t}, D b: t, where c is the type of b 

GE(?) = 

let Q = the type and row variables in r g , where T q is the built-in type for q 

T = MATCH({r, Ct}, Q U {/}), where t is fresh with respect to Q 
in | T#{r g C(}, ®Dq:Tt 

GE(x) = 0|{sC *},{z:s} 3 a::* 

GE((0, EMPTY)) = | {(0, iVt/iZ) C (& X)}, D (<£, EMPTY): (<f>, X) 

GE«</>, «)) = | {{0, X) C (0, ?)}, {u: (0, A-)} D (</>, u): (<f>, J) 

GE((/, £)) = (where / is non-empty) 

let Ri | Q,Ai D f(l):a, = GE(/(/)), for all / G dom(f) 

with the type and row variables in GE(/(/)) renamed to be distinct from those in GE(/(/')) 
for all I ^ V where /, /' G dom(f) 
Re I C E , A e D (<f,, E): (h E , Z) = GE((<f>, E)) 

with the type and row variables in GE((0, E)) renamed to be distinct 
from those in GE(/(/)), for all / G dom(f) 
Ql = the type and row variables in Ri | C/, Ai D /(0 : a U f° r ^ ' £ dom(f) 
Qe = the type and row variables in Re \ Ce, Ae D (<t>, E): (He, Z) 
T = UNIFY({a = (3 | w: a G A x and w: (3 G A v for / # /', /, /' G dom(f) 

or w: a G A; and w: /3 £ Ae for / G dom(f)}, Qe U U/g<W(/) 20) 
5 - r;MATCH(TC£; U U e <w(/) ^C, ranfire(T) UQ £ U U e <W(/) 2/)) 
in^UU^j/)^, \S.C E U U edom (/)^-C;, 5A B U U edom(/ ) ^ => </,£}: £</* + h E ,Z) 
where dom(h) — dom(f) and V7 G dom(K). h(l) — g\ 

GE(MN) = 

let R 1 \C 1 ,A 1 D M: a = GE(M) 
R 2 \C 2 ,A 2 D N:t= GE(Y) 

with type and row variables renamed to be distinct from those in GE(M) 
Qi = the type and row variables in Ri \ C\, A\ D M:a 
Q.2 = the type and row variables in R 2 \ C 2 , A 2 D N: r 
T = UNIFY({a = (3 | w: a G A a and w: (3 G ^2} U {a = r -> <}, Qi U Q 2 ) 

where t is fresh with respect to Q\ U Q 2 
5* = T;MATCH(TCi U TC 2 , range{T) U Qi U Q 2 U {/}) 
in 5i?j U SR 2 U {5r} | 5 • d U 5 • C 2 , S^i U SA 2 D MN: St 

GE(fn P => M) = 

let P p I C p , J 4 P DP:<J= GE(P) 
i? e |C e ,^e D M:t = GE(Af) 

with type and row variables renamed to be distinct from those in GE(P) 
Q p = the type and row variables in R p | C p , A p D P:a 
Q e = the type and row variables in R e \C e ,A e D M: r 
T = UNIFY({a = (3 | w: a G A p and w: (3 G A e }, Q p U Q e ) 
S = T;MATCK(TC P U TC e , range(T) UQ p UQ e ) 
in SPp U SR e I (5 • C p )°p U S • C e , (5A e - 5y4 p ) D fn P ^ ¥: 5(<r -^ r) 
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4.5 Soundness 

In this section, we prove Theorem 4.5.3, the first of the two main theorems of the thesis, 
which shows that GE is sound with respect to the _R-typing system and generates the most 
general restricted typing. More precisely, it shows that for any expression M, if GE(M) 
yields a restricted typing statement, then every instance of that restricted typing is derivable 
in the i£-typmg system. 

We will prove Theorem 4.5.3 in the following manner. We will first prove Lemma 4.5.2, 
which shows that, for any expression M, if GE(M) succeeds and yields a restricted typing, 
then that restricted typing is provable in the i?-typing system. Then, by Theorem 3.6.7, it 
follows easily that every instance of that restricted typing is provable. 

In order to prove Theorem 4.5.2, we will need to use the following fact about the action 
of GE on patterns: namely, that it infers a type environment that contains mappings for 
exactly the free variables of the pattern. 

Lemma 4.5.1 // GE(P) = R\C,A D P:a, then vars(A) = vars(P). 

We omit the proof, as it follows by a simple induction on the structure of terms. 

Using some of the lemmas developed in Chapter 3 as well as the above lemma, we 
now prove the desired lemma about the algorithm. In our proof, we extend our notion of 
unification to type environments and say informally that "S unifies A\ and A 2 " if, for all 
w such that w.a £ A\ and w. f3 G Ai for some a and (3, Sa is syntactically like 5/3. 

Lemma 4.5.2 If GE(M) succeeds and yields R \ C, A D M:a, then R\C,ADM:aisa 
provable restricted typing statement. 

Proof. The proof is analogous to [Mit84]. We proceed by induction on the structure 
of terms. 

If M is an integer 6, then GE(M) = | {int C t}, D b: t. By axiom (int), we have that 
H | 0, D b: int. Lemma 3.6.2 yields h | {int C t}, D b: int, and a use of (coerce) then 
yields h | {int C f},0 Di:(, as desired. The proof is analogous if & is a real, a boolean, or 
a string. 

If M is a variable x, then GE(M) = | {s C t},{x:s} D x:t. By axiom (var), we 
have that h | {x: s},$ D x: s. Lemma 3.6.2 yields h | {s C t}, {x: s} D x: s, and a use of 
(coerce) then yields h | {s C t}, {x: s} D x: t, as desired. 

If M is of the form (<f>, EMPTY), then GE{M) = <b\{(<j),NULL) C {<f>,X)},Q D 
(<f>, EMPTY): (cf>,X), for some X. We have that h | 0,0 D {<t>, EMPTY): {4>,NULL) by 
axiom (reel). We have that h | {(<£, NULL) C (<£, X)}, D {4>, EMPTY): (<j>, NULL) by 
Lemma 3.6.2, and we get I- | {(4>, NULL) C ((f), X)}, D (<j>, EMPTY): (i, X) by a use of 
(coerce), as desired. 

If M is of the form (<£,«), then GE(M) = $\{(<f>,X) C (<f>,y},9 D (<j>,u):{4>,X). 
By axiom (rec2), we have that h | 0, {(<f>, u): (<f>, X), D (<f>, u) :(</>, X). Lemma 3.6.2 yields 
h Q)\{(<t>,X) C <0,y>},0 D (<t>,u):(<t),X),<md a use of (coerce) then yields h 0| {<^,A"> C 

(<t>, y)h => (& u ) : {$■> y), as desired. 

If M is a built-in constant q, then GE(M) = | T»{r q C t}, D b: Tt, for some t. By the 
properties of MATCH, T is a matching substitution for {r q C r}. Thus, by axiom (const), 
we have that h | 0, D q: Tr q . Lemma 3.6.2 yields h | T* {r q C /}, D q: Tr q . By Lemma 
3.5.5, T.{r,C(}h Tr q C Tt. Thus, a use of (coerce) yields h | T • {r q C t}, D q: Tt, as 
desired. 
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If M is of the form (/, E), where / is non-empty, then we can assume inductively that 
I- R E I C E , A e D (<t>, E): (h E , Z) and that 

VZ G dom(f). h R l | Ci, Ai D /(/): /i(Z), 

where dom(h) — dom(f), and V7 € dom(h). h(l) = o\. Since, by assumption, GE succeeds, 
we can assume that h + h E is defined, and that S respects Ce and all the Q, S is defined 
on .Re and all the Ri, on Ae and all the A;, and on (h + h,E,Z). Therefore, S is also defined 
on (h E ,2). 

Thus, by Lemma 3.6.7, we have that h SR E | S • C £ , 5A £ D (<f>, E): S(h E , Z) and that 

V/ € &m(/). h ^iZ/ 1 5 • C, SAi D /(/): £(&(/)) 

Since, by assumption, GE(M) succeeds, we can assume that SAe U Ufedom(/) ^i ^ s a 
well-formed set. Thus, by Lemma 3.6.3, Lemma 3.6.2 and Lemma 3.6.1, we can infer that 

\-SR E U |J SRi\S*C E U |J S*C h SA E U |J SAiD(<j>,E):S(h E ,Z) 

ledom(f) l€dom(f) ledom(f) 

and that 

Vledom(f). \- SR E U (J SRi\S»C E U (J S»C h SA E U (J SAi D f(l):S(h(l)) 

ledom(f) ledom(f) ledom(f) 

Since, by assumption, S(h + Iie, Z) is defined, a use of (rec3) yields 
\-SR E U |J SRi\S»C E U |J S*C h SA E U (J SA t D (f,E): S(h+ h E ,Z), 

ledom(f) l£dom(f) ledom(f) 

as desired. 

If M is of the form M'N', then we can assume inductively that \- R\\C\,A\ D M'\ a, 
and that h R 2 \C 2 ,A 2 D N':t. Since, by assumption, GE(M) succeeds, we can assume 
that S respects C\ and C 2 and that S is defined on R\, R 2 , A\, A 2 , r, and t. We first need 
to show that 5" is defined on a. 

Assume for the sake of contradiction that S is not defined on a. Since, by assumption, 
GE(M) succeeds, T unifies a = r^t. Thus, it must be that MATCH(TCi U TC 2 ) is not 
defined on Ta, which implies that MATCH(rCi U TC 2 ) is not defined on T{r-*t). But 
then, S is not defined on r—*t, which leads to a contradiction. Thus, we can conclude that 
S is defined on a and unifies a = r— ►£. 

By Lemma 3.6.7, we have that h £#1 1 S • Ci,SAj, D M'\ Scr, and that h SR 2 \ S • 
C 2 , SA 2 D N': St. Since, by assumption, GE(M) succeeds, we can assume that SAi U SA 2 
is a well-defined set. Therefore, by Lemma 3.6.3, Lemma 3.6.2, and Lemma 3.6.1, we have 
that 

h SRi U SR 2 U {St} \S*C 1 US*C 2 ,SA 1 l)SA 2 D M'N': ST^St 

and that 

I- SRi U SR 2 U {St} \S»C 1 US»C 2 ,SA 1 l> SA 2 , D M'N': St 

A use of rule (app) then yields 

h Sfli U 5i? 2 U {St} I 5 • d U 5 • C 2 , 5A a U 5A 2 , D Af'JV': 5/, 
as desired. 
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If M is of the form f n P =>• M' , then we can assume inductively that \- R p \C p ,A p D P:a, 
and that h E e |C e ,A e D M' : r. Since, by assumption, GE{M) succeeds, we can assume 
that S respects C p and C e and is defined on R p , R e , A p , A e , a and r. Thus, by Lemma 
3.6.7, we have that h SR P \ S • C p , SA P D P: Sa, and that h SR e | S • C e , SA e D M': St. 
Since, by assumption, S unifies A p and A e , we have that 

(SA e )[SA p ] = 5A P U SA e 

and is a well-defined set. Thus, by Lemma 3.6.3, Lemma 3.6.2, and Lemma 3.6.1, we can 
conclude that 

h SR P USR e \S*C p U(S» C e ) op , SA P D P: Sa 

and that 

h SR P U SR e | (S • C p ) op U 5" • C e , (5A e )[5A p ] D W: St. 

By Lemma 4.5.1, we can infer that vars(A p ) = vars(P). Since vars(SA p ) = vars(A p ), 
a use of rule (abs) yields 

h SR P U SR e | (5 • C p ) op U 5 • C e , S^ e DfnP=> M': ^(ct-^t). 

Since vars(fn P =>• M') = i;ar.s(M')-i;ar.s(P), we have by Lemma 3.6.3 that vars(SA e ) D 
vars(M') - vars(P). Thus, since vars(SA e - SA P ) = t;ars(5Ae) - vars(P) D vars(M') - 
vars(P), we have by Lemma 3.6.3 that 

h SR P U 5i? e | (S • C p ) op U S • C e , SA e - SA P D fn P =► M': 5(a->r), 

proving the theorem. ■ 

We now formally state the main theorem concerning the soundness of GE with respect 
to the i?-typing system. 

Lemma 4.5.3 If GE(M) succeeds and yields R \ C, A D M:a, then every instance of 
R | C, A D M: a is provable. 

The proof follows easily by Lemma 4.5.2 and Lemma 3.6.7. 

4.6 Completeness 

This section proves Theorem 4.6.4, the second main theorem of this thesis, which shows 
that GE is complete with respect to the i2-typing system and generates the most general 
restricted typing. More precisely, it shows that for any expression M, if a restricted typing 
for M is derivable in the P-typing system, then GE yields a restricted typing statement of 
which the provable restricted typing for M is an instance. 

In our proof of Theorem 4.6.4, we will need to use an induction on the structure of terms 
in ML + ; that is, for any typable expression M, we will show inductively that the antecedents 
in the derivation of a provable typing for M are instances of the typing yielded by GE on 
the corresponding subexpressions of M. However, due to the rule (coerce) there may be 
many possible derivations for a provable typing, and thus, our inductive reasoning becomes 
more complicated. In order to simplify this reasoning, we show that, as in [Mit84], every 
typing derivation may be put in a certain "normal form", in which the rule (coerce) is used 
only after the axioms in the typing system. Reasoning about the normal form derivation of 
provable typings greatly simplifies our proof of Theorem 4.6.4. 

47 



Lemma 4.6.1 Suppose R\C,A 3 M:a is provable. Then there is a derivation with pre- 
cisely the same cut formulas in which rule (coerce) is used only immediately after the typing 
axioms (int), (real), (bool), (string), (var), (reel), (rec2), and (const). 

Proof. The proof is similar to that of [Mit84]. We think of the proof of a restricted 
typing statement as a tree, where each leaf is an instance of the axiom (int), (real), (bool), 
(string), (var), (reel), (rec2), or (const). We think of each node as labeled by both the 
restricted typing statement proved at that node and the final rule used in that proof. Given 
a proof of a restricted typing statement, we define the degree of the proof to be the number 
of pairs of internal tree nodes (a,/3) such that there is a path from a leaf through a to /3 
and node (3 is labeled with (coerce). Intuitively, the degree of the proof gives a measure of 
how far the the occurrences of (coerce) are from the leaves. We note that a proof has degree 
zero iff the rule (coerce) is used only immediately after the axioms and show by induction 
on the degree of a proof that every provable statement has a proof of degree zero. 

If the final two rules used in the proof are both (coerce), then h R \ C, A D M:a must 
have followed by the antecedents h R \ C, A D M:j and C h 7 C o for some 7. Also, 
h R I C, A D M: 7 must have followed by the antecedents \- R\C,AD M:t and C \- r C 7 
for some r. By (trans), we can infer that 

C h r C a. 

Therefore, we can derive h R\C,A D M:a directly from h R \ C, A D M:t by (coerce), 
thus reducing the degree of the proof. 

If the final two rules used in the proof are (app) followed by (coerce), then M is of 
the form M — M'N' and h R\C, A D M:a must have followed by the antecedents h 
R\ C, A D M'N':f and C h 7 C u for some 7. Also, for some r, where R — R' U {r}, 
h R I C, A D M'N': 7 must have followed by the antecedents h R'\C,A D M': r— »7 and 
r- R' I C, A D N': t. By (arrow), we can infer that 

C h r— >7 C r-^a. 

Thus, we can derive h R' \ C, A D M'\ r— >a directly from h R' \ C, A D M'\ r— >7 by (coerce), 
and then proceed to derive h R \ C, A D M'N': a by (app), thus reducing the degree of the 
proof. 

If the final two rules used in a proof are (abs) followed by (coerce), then M is of the form 
M = fn P =>• M' and a is of the form a - a 1 -^a 2 . Thus, h R | C, A D fn P =>• M': ai^a 2 
must have followed by the antecedents h R \ C, A D fn P =>• M': 71— >72 and C \- 71—^72 Q 
o~i—>&2 for some 71 and 72. Also, h R | C, A D fn P =J> M': 71— >72 must have followed by 
the antecedents h i2|C op ,A' D P: 7 a and t- R\C,A[A'] D M': 72 for some A' such that 
■yar-s(A') = vars(P). By Lemma 3.5.2, 

C h (7i C 7! and C h 72 C (72; 

thus, C° v h 7x C <7i. Therefore, we can derive h i2 | C op , A' D P: <Ti directly from h 
R\C° V ,A' D P:7i by (coerce) ,and we can derive h P | C, A[A'] D M':a 2 directly from 
\- R\C, A[A'] D M': 72 by (coerce). We can then proceed to derive h P | C op , A D f n P =J» 
M': Ox-^Oi by (abs), thus reducing the degree of the proof by 1. 

If the final two rules used in a proof are (recS) followed by (coerce), then M is of the 
form M = (f,E), and a is of the form a = (h,Z), where dom(f) ^ (f> and dom(h) ^ <f>. 
We can thus assume that, for some (h',Z') where dom(h') = dom(h), \- R \ C, A D M:a 
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must have followed by the antecedents h R\C,A D M:(h',Z') and C h (ft', 2') C (h,Z). 
Also, we can assume that \- R\C,A D M: (h f , Z') must have followed by the antecedents 
VZ G dom(/). h i2 | C, A D /(/):/»i'(0 and h i? | C, A D (<f>,E): (h 2 ',Z') for some V and 
/i 2 ', where /i' = /i/ + Zi 2 '. By Lemma 3.5.3, 

C\-(<j>,Z')C(<l>,Z), 

and 

VZ G doro(ft). C r- h(l) C ft'(Z). 

Since dom(h) = dom(h') and dom(h\) l~l dom(h 2 ) = <f>, we can divide ft into ft = fti + /12, 
where dom{h\) = dom(hx) and dom(h 2 ) = dom(h 2 ). Since ft 2 C ft, we can infer by (record) 
that 

ch(/j 2 ',z / >c(/ l2 ,2). 

We can then derive \- R\C,A D ((f>,E): (h 2 , Z) directly from \- R\C,A D ((f>,E): (h 2 ', Z') by 
(coerce). Moreover, for all / G dom(f), we can derive \- R\C,AD /(Z): Zii(Z) directly from 
I- R I C, A D /(/): /ii'(Z) by fcoerce;, since Zi a C ft. We can then derive \- R\C,A D M:{h, Z) 
by (rec3), reducing the degree of the proof by 1, and proving the lemma. ■ 

In our proof of Theorem 4.6.4, we will need the following property about the action of 
GE on record expressions which contain no explicit labels: namely, that such records are 
always inferred to be of a record type whose first component is the empty function. 

Lemma 4.6.2 IfGE({<f>,E)) = R\C,A D {<f>,E): (h,Z), then dom(h) = <}>. 

The proof proceeds by simple case analysis. 

We will also need the following property of substitutions, which shows that, in a precise 
technical sense, substitution composition merges naturally with the operation •. 

Lemma 4.6.3 Suppose that Q is a set of type variables and row variables and that C is 
a set of possibly non-matching subtype assertions that contains only type variables and row 
variables from Q. Furthermore, suppose that S, T and W are substitutions such that T; S 
is defined and W =q T; S. IfW and T are matching substitutions for C, then 

1. S respects (T • C) 

2. S*(T»C)\-W»C 

3. W»ChS»(T»C) 

Proof. To prove (1), we note that, clearly, S is a matching substitution for TC. It 
is easy to show by induction on the structure of terms that S must respect T • C. 

To prove (2), we note that, by Lemma 3.5.5, T • C h TC. By Lemma 3.6.5, we have 
that 

Vct' C t' G TC. S • (T • C) I- AT0MIC(5V C St') 

Thus, it follows that Vct C r G C. S • (T • C) \- ATOMIC(S(IV) C S(Tt)). Therefore, 
S • (T • C) h (T; S) • C. Since C contains only type variables and row variables from Q, 
we have that W • C = (T; S) • C, as desired. 

To prove (3), we note that, clearly, (T; S) respects C. By Lemma 3.5.5, it follows that 

Vct C r G C. (T; S) • {a C r} h (T; S){a C r}. 
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By induction on the structure of terms and by Lemma 3.5.2 and Lemma 3.5.3, it is easy 
to show that 

VaCreC. (T; S) • {a C r} I- \J {So' C St'} 

*«ZT>eATOMIC(T*cTT) 

By Lemma 3.5.5, 

Ma C r € C. (T; S) • {o C t} \- [j ATOMIC (SV C St') 

<7'Ct'gAT0MIC(7VCTt) 

Thus, we have that (T; S) • C h 5 • (T • C). Since C contains only type variables and row 

variables from Q, W • C = (T; S) • C, proving the lemma. ■ 

Using the above lemmas as well as some of the lemmas developed in Chapter 3, we now 

prove our main theorem about the completeness of GE with respect to the .R-typing system. 

Theorem 4.6.4 // h R \ C, A D M: 7, then GE(M) succeeds and produces a restricted 
typing statement with R | C, A D M: 7 as an instance. 

Proof. The proof is similar to [Mit84], except that we show that the substitution 
which provides the instance is defined on GE(M). We proceed by induction on the structure 
of terms. 

Suppose that M is an integer 6, and that h R | C, A D b: 7. By Lemma 4.6.1, we can 
assume without loss of generality that the proof consists of a use of (int) followed by a use 
of (coerce). Thus, C h int C 7. By Lemma 3.5.1, we can conclude that int matches 7. 

It is easy to see that GE(b) always succeeds. It remains to show that h R \ C, A D b: 7 is 
an instance of GE(b) by some substitution S. Let S = [f/t]. Clearly, S respects {int C t}. 
Thus, by Lemma 3.5.5, we can conclude that C h S • {int C t}, giving the proof of this 
case. The proof is analogous if 6 is a real, a boolean, or a string. 

Suppose that M is an variable x, and that h R | C, A D x: 7. By Lemma 4.6.1, we can 
assume without loss of generality that the proof consists of a use of (var) followed by a 
use of (coerce). By Lemma 3.6.3, x must occur in A. Let r be the type expression with 
x: tEA, and note that C h r C 7. By Lemma 3.5.1, 7 and r must match. 

It is easy to see that GE(x) always succeeds. It remains to show that h R \ C, A D x: 7 
is an instance of GE(x) by some substitution S. Let S = [j/t, t/s]. Clearly S respects 
{s C t}; thus, by Lemma 3.5.5, we can conclude that C h S • {s C t}. Moreover, since 
x:t £ A, it follows that A D S{x: s}, completing the proof of this case. 

Suppose that M is of the form {(j), EMPTY) and that h R \ C, A D M:j. By Lemma 
4.6.1, we can assume without loss of generality that the proof consists of a use of (reel) 
followed by a use of (coerce). Thus, C (- {<f>, NULL) C 7. By Lemma 3.5.1, we can conclude 
that (4>,NU LL) matches 7. Thus, 7 = (4>,Z) for some Z. 

It is easy to see that GE((<f>, EMPTY)) always succeeds. It remains to show that 
R\C,A D (<j>, EMPTY):-) is an instance of GE((<f>, EMPTY)) by some substitution S. 
Let 

S = [(<!>, Z)/X] 

Since 7 = S(<j>,X), it follows that S respects {{4>,NULL) C (0, X)}. Thus, by Lemma 
3.5.5, we have that C h S • {{<j>, NULL) C (0, X)}, completing the proof of this case. 

Suppose that M is of the form (<j>, u) and that h R \ C, A D M: 7. By Lemma 4.6.1, we 
can assume without loss of generality that the proof consists of a use of (rec2) followed by 
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a use of (coerce). By Lemma 3.6.3, u must occur in A. Let (h,Z) be the type expression 
with u:(h,Z) € A, and note that C h (/i,2) C 7. By Lemma 3.5.1, 7 and (h,Z) must 
match. Thus, 7 = (h',Z') for some /*' and Z' such that dom(h) = dom(h') and VZ e 
dom(h). h(l) matches //(/). 

It is easy to see that GE((<f>,u)) always succeeds. It remains to show that R | C, A D 
(<f>, u): 7 is an instance of GE((4>, u)) by some substitution S. Let 

s = [(h',z')/y, (h,z)/x] 

Clearly, S respects {{<j>,X) C {<f>, y)}; thus, by Lemma 3.5.5, we can conclude that C h 
S • {(<t>,X) C (4>,y)}. Moreover, since u:(h,Z) <E A, it follows that A D S{u:(<f>,X)}, 
completing the proof of this case. 

Suppose that M is a built-in constant q and that h R \ C, A D q: 7. By Lemma 4.6.1, 
we can assume without loss of generality that the proof consists of a use of (const) followed 
by a use of (coerce). Thus, we can assume that, for some substitution V that is defined on 
T q , (where r q is the built-in type for q), C r- Vr q C 7. By Lemma 3.5.1, Vr q and 7 must 
match. 

Let Q! = Qll{t}. Also, let W be the substitution with dom(W) = Q! and such that, for 
all type variables and row variables in Q, W behaves identically to V\ furthermore, Wt = 7. 
Clearly, W is defined on r q and Wr q — Vr q ; therefore, If is a matching substitution for 
{r q C i). By Lemma 4.3.6, MATCH({r g C t}, Q!) succeeds, and W = Q > T; U for some 
substitution U where T; U is defined. Also by Lemma 4.3.6, dom(T) C Q'; thus, T\Q' = T. 
Therefore, since dom(W ) = Q', 

W = T; [/', where [/' = U\(range(T) U Q'). 

It remains to show that R \ C, A D ^r: 7 is an instance of GE(q) by some substitution 
5. Let S = U'. Then, by Lemma 4.6.3, S respects T • {r q C <}, and W • {r, C *} h 
5 • (T • {r, C <}). Since iy.{r,Cl} = ATOMIC(Fr ? C 7), we have by Lemma 3.5.5 that 
C h W • {r g C f), completing the proof of this case. 

Suppose that M is of the form M'N' and that h R\C,A D M:-y. By Lemma 4.6.1, we 
can assume without loss of generality that the proof ends in a use of (app). Thus, for some 

7', 

h R' I C, A D M': 7^7 

and 

\- R'\C,AD N'-.j 1 , 

where R' — RL) {7'}. We can assume inductively that R! \ C, A D M': 7'— >7 is an instance 
of GE(M') = R 1 \C 1 ,A 1 D M'\ a and that R'\C,AD N': 7' is an instance of GE(N') = 
R 2 I C2, A 2 D N': t. Thus, there exist substitutions Vy and V 2 such that V\ respects C\ and 
is defined on R\, A\, and a, V 2 respects C 2 and is defined on R 2 , A 2 , and r, and such that 

R' 2 ViRu C\-Vi»C u AD VtAi, 7'->7 = V x a 

and 

R' D V 2 R 2 , ChV 2 »C 2 , AD V 2 A 2 , i = V 2 t. 

We note that no type or row variable in Qi appears in Q 2 , and that t is not contained 
in Q\ or Q 2 . Thus, there exists a well-defined substitution V whose domain is {/} U Q\ U Q 2 
and such that V maps any type variable s in its domain to V\S if s G Q\ and to V 2 s if 
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s € Q 2 . (The analogous definition holds for row variables in the domain of V.) Also, V 
maps t to 7. 

It is easy to see that V respects C\ and C 2 and is defined on R\, R 2 , A\, A 2 , <J and r, 
and that 

R' D VR U C h V • Ci, AD VA 1} 7 '-> 7 = F<r 

and 

£' 2 VR 2 , C\-V*C 2 , AD VA 2 , 7' = Vt. 

Therefore, V must unify {a = (1 \ w: a € Ai and u?:/3 e A 2 }. Also, since Vt = 7, we 
have that Va = Fr^Fi = V(r->t); thus, V unifies ct = r-*t. Let Q = Q a U Q 2 U {*}• 
By Lemma 4.2.1, it follows that T = UNIFY({a = (3 \ w: a £ A x and w: /3 € A 2 } U {a = 
r— >■<}, Q) succeeds, and that V =q T;U for some substitution £/ such that T; U is defined. 
Equivalent^, V =q T; U', where U' = U\{range(T) U Q). 

Since only type and row variables from Q occur in C\ and C 2 , clearly U' respects (TC\ U 
TC 2 ). Therefore, by Lemma 4.3.6, we can assume that MATCH(TCi U TC 2 , range(T) U Q) 
succeeds. Furthermore, letting V = MATCH(TCi U TC 2 ,range(T) U Q), we have that 
U' -range(T)uQ T'\W for some substitution W where T';W is defined. Since dom(U') C 
(range(T) U Q), and since, by Lemma 4.3.6, dom(T') C (range(T) U Q), we have that 

£/■' = (T'; W) \(range(T) UQ) = T'; VF \(range(T') U range(T) U Q). 

Thus, since T; i/' is defined, so is T;(T';W\(range(T') U range(T) U Q)), and thus so is 
S = T- T'. Therefore, V = Q T; T'\ W = Q S; W. 

We recall that all the type variables and row variables occurring in any of C\, C 2 , R\, 
R 2 , Ai, A 2 , a, t, and t, are contained in Q. Thus, S respects C\ and C 2 and is defined 
on Ri, R 2 , Ai, A 2 , a and r. Since T unifies Ai and A 2 , so does S. Thus, SAi U SA 2 is a 
well- formed set. Furthermore, since V =q S; W, it is easy to see that W is defined on SR\, 
SR 2 , SAi, SA 2 , Sa and St. By Lemma 4.6.3, we have that W respects S • Ci and S • C 2 
and that C \- W • (S tdU S • C 2 ). 

Clearly, W(St) = 7, A D W{SAi U SA 2 ), and R' D W(SRi U 5^2). Since Vt = 7', we 
have that R = R'U W(St). Thus, R D W(SRi U SR 2 U 5"r). Therefore, R \ C, A D M'N': 7 
is an instance of GE(M'N') by substitution W. 

Suppose that M is of the form fn P => M' and \- R\C, A D M:f. By Lemma 4.6.1, we 
can assume without loss of generality that the proof ends in a use of (abs). Thus, for some 
A', 71, and 72, where vars(A') = vars(P) and 7 = 71— >7 2 , 

h iZlC^A' D P: 7l 

and 

\-R\C,A[A']DM': l2 . 

We can thus assume inductively that R\C op ,A' D P: 71 is an instance of GE(P) = 
if!p I C p , A p D P:a and that i? | C, A[A'] D M': 72 is an instance of GE{M) = R e \ C e , A e D 
M': r. Thus, there exist substitutions V p and V e such that V p respects C p and is defined on 
R p , A p , and a, V e respects C e and is defined on R e , A e , and r, and such that 

R D V P R P , C op \-V p * C p , A' D VpAp, 71 = V v a 

and 

R 2 V e R e , C\-V e * C e , A[A'} D V e A e , l2 = V e T. 
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Since no type or row variables in Q p appear in Q e , we can define the substitution V 
whose domain is Q p U Q e and such that V maps any type variable t in its domain to V p t if 
t e Q p and to V e t if t 6 Q e . The action of V on row variables in its domain is analogous. It 
is easy to see that V respects C p and C e , is defined on R p , R e , A p , A e , a and r, and that 

R D VR p , C op \-V» C p , A' D VA P , 7l = Va 

and 

R D VR e , ChV»C e , A[A'} D VA e , 72 = Vt. 

By Lemma 4.5.1, vars(A p ) = vars(P). Thus, A' = VA p , and thus, A[FA p ] D VA e . This 
implies that if w: Va G VA e and w: V/3 € VA P , then Va = Vf3. Let Q = Q p U Q e . By 
Lemma 4.2.1, it follows that UNIFY({a = /3 \ w: a 6 A p and w: (3 £ A e }, Q) succeeds, and 
that V -q T; U for some U such that T; ?7 is defined. Equivalently, V = Q T; U', where 
U' = U\(range(T)uQ). 

Since only type and row variables from Q occur in C p and C e , clearly U respects (TC P U 
TC e ). Thus, by Lemma 4.3.6, we can assume that that MATCK(TC p UTC e ,range(T)l> Q) 
succeeds. Furthermore, letting T' = MATCH(TC P U TC e ,range(T) U Q), we have that 
U' =range{T)uQ T' \ W for some substitution W where T"; W is defined. Since dom(U') C 
(range(T) U Q), and since, by Lemma 4.3.6, dom(T') C (range(T) U Q), we have that 

[/' = (I"; W) t(ran ff e(T) U Q) = T'; W \(range(T') U range(T) U Q). 

Thus, since T; t/ - ' is defined, so is T; (T';W\(range(T') U range{T) U Q)), and thus so is 
5 = T; T'. Therefore, V =q T; T'; W =q S; W. 

We recall that all the type variables and row variables occurring in any of C p , C e , R P , 
R e , A p , A e , a, and r, are contained in Q. Clearly, 5* respects C p and C e and is defined 
on R p , R e , A p , A e , a and r. Since T unifies A p and A e , so does S. Thus, SA e — SA P is 
a well-defined set. Furthermore, since V = S; W , it is easy to see that W is defined on 
SRp, SR e , SA P , SA e , Sct and St. By Lemma 4.6.3, W respects S • C p and S • C e and 
C h W • (S • C p op U S • C e ). It is easy to see that 

W(So^St) = 71-^72, and R D W(SR P U SR e ). 

Since A' = W(SA P ), we know that A [A'] = Ai U W(5 A p ), where A = Ai U{w: a | iu: a € 
Aandw:/? € I4 y (5 , A p )}. (Note that these are "disjoint" unions, since these sets are 
well-formed.) If w:a e W(SA e - SA P ), then to g vars(VK(5 , A p )). Thus, since A[A'] 2 
^^Ae) D VF(5A e - 5A P ), w: a £ A r . Thus, tu: a € A, and therefore A D W(SA e - 5A P ), 
as desired. 

Thus, R | C, A D fn P =>• M': 7 is an instance of G^fn P => M') by substitution W. 

Suppose that M is of the form (f,E), where / is non-empty, and h R \ C, A D M:*y. 
By Lemma 4.6.1, we can assume without loss of generality that the proof ends in a use of 
(rec3). Therefore, we can assume that for some hi, /i2> and Z' where hi +h 2 is well-defined, 
dom(f) — dom(hi), and 7 = (hi + h2,Z'), 

\- R\C,AD (<f>, E): {h 2 , Z') 

and 

V/ € dom(f). \- R\C,AD /(/): /i^/). 
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We can thus assume inductively that R \ C, A D (<f>, E): (h 2 , Z') is an instance of GE((<f), E)) = 
R E \C E ,A E D (<f), E): (h E , Z) and that for all / G dom(f), R | C, A D /(f):J»i(0 is an in- 
stance of GE(f(l)) = Ri | C h Ai D /(/): h{l). 

Thus, there exists a substitution V E such that Ve respects Ce and is defined on R E , 
Aei and (He, Z) and such that 

R 2 V e Re, ChV E »C E , AD V E A E , (h 2 ,Z') = V E {h E ,Z). 

Also, for all / G dom(f), there exists a substitution Vj such that V; respects C\ and is defined 
on R\, A], and /i(/) and such that 

R D ViRi, Ct-VfCi, AD ViAi, /n(Z) = V,(/i(/)). 

Since the type and row variables that occur in Q E and in the Qi are all distinct there 
is a well-defined substitution V whose domain is Q E U \Jiedom(f) Qh and such that for all 
type variables t in its domain, Vt — VeI if t G Qe, and, for any / G dom(f), Vt = Vrf if 
/ G Qi- An analogous definition holds for the action of V on row variables in its domain. 

It is easy to see that V respects Ce and is defined on Re, A e and (h E , Z) and that, for 
all / G dom(f), V respects C\ and is defined on R\, A\, and h(l). Moreover, we have that 

R D VR E , C\-V»C E , AD VA E , (h 2 , Z') = V(h E , Z). 

and for all / G dom(f), 

R D VRi, C\-V»Ci, AD VA h h^l) = V(h(l)). 

Let Q = Q E U Uiedom(f) Qi- Since V must unify A E and all of the At, we can con- 
clude by Lemma 4.2.1 that T = UNIFY({a = (3 \ w: a G A t and w: /3 G A v , for/ ^ 
/', /,/' G dom(f), ot w.a G A\ and w: /3 € A E , for Z G dom(f)}, Q) succeeds. Further- 
more, V =g T; U for some C/ such that T; £/ is defined. Equivalently, V =q T; [/', where 
U' = U\(range(T)uQ). 

Since only type and row variables from Q occur in C E and all the C\, clearly U 
must respect TC E and all of the TC\. Thus, by Lemma 4.3.6, we can assume that that 
MATCH(TCe U [Jiedom(f) TCi, range(T) U Q) succeeds. Furthermore, letting 

T' = MATCH(rCE U |J TCi, range(T) U Q), 

ledom(f) 

we have that U' — ra nge(T)uQ T'; W for some substitution W where T"; W is defined. Since 
dom(U') C (range(T) U Q), and since, by Lemma 4.3.6, dom(T') C (range(T) U Q), we 
have that 

Z7' = (T'; W) \{range(T) UQ) = T'; W r(ra^e(T') U range(T) U Q). 

Thus, since T; C/' is defined, so is T; (T'; W\(range(T') U range(T) U Q)), and thus so is 
5 = T; V. Therefore, V = Q T; T'\ W = Q S; W. 

We recall that all the type variables and row variables occurring in C E , A E , Re, (h E , Z), 
any of the C), Ri, Ai, o\, are contained in Q. Thus, S respects Ce and all the C\, and is 
defined on Re and all the Ri, on A E and all the A\, and on (h E , Z) and all the h(l). Since 
T unifies Ae and all the Ai, so does S; thus, SA E U Uiedom(f) $Ai is well- formed. 
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It is easy to see that W is defined on SR E and all the SRi, on SA E and all the SAi, 
and on S (h E , Z) and all the S(h(l)). By Lemma 4.6.3, W respects S •C E and all the S»Ci 
and 

c\-w*(s»c E u U s • C,). 

Clearly, 

ledom(f) ledom{f) 

All that remains to be shown is that h + h E is well-defined, 5 is defined on (h + h E ,Z), 
W is defined on S(h + h E , Z), and that (hi + h 2 , Z') = W(S(h + h E , Z)). 

By Lemma 4.6.2, h E = <t>- Thus, (h + h E ,Z) = {h,Z), and is well-formed. Then, 
V(h + h E ,Z) = (h;V+left(V((/>,Z)),right(V{<t>,Z))) = (h 1 + h 2 ,Z). Since, by assumption, 
h x + h 2 is well-defined, so is V{h + h E , Z). Then, so is S(h + h E ,Z) and W(S(h + h E , Z)). 
Furthermore, W(S(h + h E ,Z)) = (hi + h 2 , Z). 

Thus, R | C, A D (/, E): 7 is an instance of GE((f, E)) by substitution W, proving the 
theorem. ■ 

4.7 Relating GE to the Original Typing System 

In this chapter, we have shown that the type inference algorithm GE is sound and complete 
with respect to the iZ-typing system. However, the reader may wonder how GE relates to 
the original typing system defined in Chapter 3. 

If we say that an unrestricted typing C,AD M: a is an instance of R' \ C, A' D M: a' by 
substitution S whenever S is defined on R' and C, A D M: a is an instance of C, A' D M: a' 
by 5", we have the following corollaries for soundness and completeness. 

Corollary 4.7.1 Suppose that GE(M) succeeds and produces a restricted typing statement 
R\C,AD M:a. IfC, A' D M: a' is an instance of R\C,A D M:a, then h C", A' D M: a'. 

The proof follows easily by Theorem 4.5.2 and Lemma 3.6.7. 

Corollary 4.7.2 If\~C,ADM:a, then GE(M) succeeds and produces a restricted typing 
statement with C,Ad M:o as an instance. 

The corollary is proved by noting that if C, A D M: a is provable, then there is a proof 
using some set of cut formulas. 

Therefore, given an expression M, GE computes a most general restricted typing state- 
ment for M such that C,AD M:a is provable in the original typing system iff it is an 
instance of this most general restricted typing statement. 
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Appendix A 

Unification: Algorithm and Proof 
of Correctness 



This appendix is devoted to proving Lemma 4.2, which states that an algorithm UNIFY 
exists that, given a set E of equations between types and a co-infinite set Q of type variables 
and row variables, computes a most general unifier for E of equations with respect to Q. In 
this appendix, we present the algorithm UNIFY, which uses an algorithm UNIFIER that 
we also present here. In order to prove that UNIFY is correct, we use some properties 
about most general unifiers for equations between certain types. We prove these properties 
in Lemmas A.l, A. 2, and A. 3, and then use these lemmas to prove Lemma 4.2. 

Our algorithm UNIFIER is quite similar to the unification algorithm of [Wan87]; how- 
ever, it fixes a bug in Wand's algorithm for the case of unifying two extended records. As 
we will discuss in the proof of Lemma 4.2, Wand's termination proof is incorrect, since the 
halting measure does not necessarily decrease after every iteration of the algorithm. We fix 
this bug by using some of the properties of unification developed in Lemma A. 3 in defining 
our algorithm UNIFIER, and we prove that UNIFIER does terminate. 

The algorithm UNIFIER is defined as follows: 

UNIFIER^, Q) = <f> 

UNIFIER(£' U {ci = c 2 }, Q) = 
if c\ jL c 2 then fail 

else UNIFIER(£',g) 

UNIFIER(£' U {<r x ^a 2 = n^r 2 }, Q) = 
UNIFIER(£' U {ct! = n, a 2 = r 2 }, Q) 

UNIFIER(£' U {t = r}, Q) = 

if t = r then UNIFIER(£',Q U {/}) 
else if / occurs in r then fail 

else let Q' = Q U {t} U {the type and row variables in r} 
in[r/*];UNIFIER([r/*]£', Q') 

UNIFIER(£' U {(h,NULL) = (h',NULL)}, Q) = 
if dom(h) ^ dom(h') then fail 

else UNIFIER(£' U \J, edom(h) {h(l) = h'(l)}, Q) 
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UNIFIER(£' U {(h, X) = (/»', X)}, Q) = 
if dom(h) ^ dom(h') then fail 

else UNIFIER(£' U [j ledom{h) {h(l) = h'(l)}, Q U {X}) 

UNIFIER(£' U {(h, X) = (ft', NULL)},Q) = 
if dom(h) <J- dom(h') then /a?7 

else let hi = h'\(dom{h') — dom(h)) 

in if A* occurs in {hi, NULL) then /ai7 

else let Q' = Q\J {X} U {the type and row variables in the range of hi} 

in [(hi,NULL)/X];XJmFIER([(hi,NULL)/X](E'U \J l£dom(h) {h(l) = h'(l)}), Q!) 

UNIFIER(£' U {{h, X) = (h' , X')}, Q) = (where X # X') 
let hi = h! ' \{dom{h') — dom(h)) 
h 2 = h\(dom(h) — dom(h')) 

Qe = the type and row variables in E' U {{h, X) — {h', X')} 
y be a fresh row variable with respect to QU Qe 
in if X occurs in (hi,y) or X' occurs in (h2,y) 
OR 
if X occurs in (h 2 ,y) and X' occurs in (hi,y) 
then fail 

else let V = [(hi,y)/X, (h 2 ,y)/x'];[{hi,y)/x, (h 2 ,y)/x>] 

Q' = Q U {X, X'} U {the type and row variables in the range of hi or h 2 } 
in V- UNIFIER^' U Ui edom{h) ndo m (h>){h(l) = h'(l)}), Q') 

UNIFIER^' U {a = r}, Q) = 

if a = t is an equation between any other types 
then fail 



Using this algorithm UNIFIER, we define our algorithm UNIFY, which simply checks 
that the substitution returned by UNIFIER is defined on all the types in the original set of 
equations. We define UNIFY as follows: 

UNIFY(£, Q) = 

let S =UNIFIER(£, Q) 

if, for all a = t £ E, S is defined on a and r 
then return S 
else fail 



Before proceeding to prove the correctness of UNIFY, we first develop some properties 
of unification that we will need in that proof. The first such property concerns unifying a 
type variable with a type. 

Lemma A.l A substitution T unifies E' U {t = r} iff t = r and T unifies E' OR 
1. t ^ t and 
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2. t does not occur in r and 

3. there exists a substitution V such that [T/t];T' is defined, and T = [r/t];T', and T' 
unifies [r/t]E'. 

We omit the proof, as it is quite similar to [Rob65]. 

We also need the following property about unifying an extended record with a fixed record. 
Lemma A. 2 A substitution T unifies E' U {(h,X) = (h',NULL)} iff 

1. dom(h) C dom(h') and 

2. X does not occur in (hi, NULL), where hi = h'\{dom(h') - dom(h)) and 

3. [(h 1 ,NULL)/X](E'U\J ledom{h) {h(l) = h'(l)}) is defined and 

4. there exists a substitution T such that [(h lt NULL)/X];V is defined andT = [(h lt NULL)/X]; T 
andV unifies [(h 1 ,NULL)/X](E f U{j ledom{h) {h(l) = h'(l)}) 

Again, we omit the proof, as it uses the same sort of reasoning as the proof of the Lemma 

A.l. 

The final property that we will need concerns unifying two extended records. 

Lemma A. 3 Suppose that E = E' U {{h,X) = (h',X')}. Let Q be a co-infinite set of 
type variables and row variables, and let Qg be the set of type variables and row variables 
occurring in E. Also, let V = [{h u y)/X, {h 2 ,y)/X']; [(h 1 ,y)/X, (h 2 ,y) / X 1 ], for some row 
variable y that is fresh with respect to Q U Qe- A substitution T unifies E iff 

1. X does not occur in (h\,y), where h\ = h' \(dom(h') — dom(h)) and 

2. X' does not occur in (h2,y), where h 2 — h\(dom(h) — dom(h')) and 

3. either X does not occur in (h 2 ,y) or X' does not occur in (h\,y) and 
4- V is defined and 

5. V{E' U \Jl&dom(h)ndom(h'){ h O) = h '( 1 )}) is defined and 

6. there exists a substitution T' such that V;T' is defined and T =<2ue B V;T' and T' 
unifies V(E' U\Jiedom(h)ndom(h>){K l ) = h '( 1 )}) and 

7. T is defined on (h,X) and (h',X'). 
Again, we omit the proof here. 

Using the lemmas developed above, we now give the proof of Lemma 4.2. 

Lemma 4.2 Let E be a set of equations of the form a — r and let Q be a co-infinite set 
of type variables and row variables. Let Qe be the set of type variables and row variables 
that occur in E. There exists an algorithm UNIFY such that whenever there is a unifying 
substitution for E, UNIFY(E, Q) produces a most general unifying substitution with respect 
toQuQ E . Otherwise, UNIFY (E,Q) fails. 

Proof. In order to prove the lemma, it is sufficient to show the following three 
properties of UNIFIER: 
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1. UNIFIER(£, Q) halts. 

2. If there is a substitution T that unifies E, then UNIFIER(£, Q) succeeds and produces 
a substitution S such that S unifies E. Furthermore, there exists a substitution U 
such that S; U is defined and T =quq e S; U. 

3. If there is no unifying substitution for E, then UNIFIER(£, Q) either fails or produces 
a substitution S such that for some a = t <E E, S is not defined on at least one of a 
and t. 

In order to prove (1), we define the degree of a set E to be the pair (to, n), where to is the 
number of distinct type variables and row variables that occur in E, and n is the number 
of occurrences of -►, () plus the total number of (possibly non-distinct) type variables, row 
variables, ground types, and NULL that occur in E. We say that (m,n) is smaller than 
(to', n') if either to < m', or to = to' and n < n'. We will show that each clause of the 
algorithm reduces the degree of the set E that is passed around. We note here that a set 
E has degree (0, 0) iff E is empty. 

The proof proceeds by induction on the structure of a = r, where E = E' U {a = r}, 
and (to, n) is the degree of E. 

Suppose that a — r is of the form cy = c 2 . To prove (1), we note that, clearly, the 
degree of E' is (to, n — 2). To prove (2) and (3), we note that the degree of E' is smaller 
than the degree of E, and that Q E = Q' E . The proof of (2) and (3) then follows easily from 
the inductive hypothesis. 

Suppose that a = t is of the form c^— ><7 2 = T\— >T2. To prove (1), we observe that, 
clearly, the degree of E' is (to, n — 2). To prove (2) and (3), we first note that a substitution 
T unifies E iff T unifies E' U {a\ = t\, a 2 = r 2 }. We also note that the degree of E' U {a-y — 
71,02 = T 2) is smaller than the degree of E, and that both of these sets contain the same 
type variables and row variables. The proof of (2) and (3) again follows easily from the 
inductive hypothesis. 

Suppose that a — t is of the form (h,NULL) = (h',NULL). To prove (1), we observe 
that, clearly, the degree of E' is (to, n — 4). To prove (2) and (3), we first note that a 
substitution T unifies E iff dom(h) = dom(h') and T unifies (E' U U/edom(/i){' i (0 = ^'(0))- 
We also note that the degree of (£" U UfedomfftjIKO = ^'(0)) ^ s sma U er than the degree 
of E, and that both of these sets contain the same type variables and row variables. The 
proof of (2) and (3) again follows easily from the inductive hypothesis. 

Suppose that a = r is of the form (h, X) = (h', X). To prove (1), we note that, clearly, 
the degree of E' is (to, n — 4). To prove (2) and (3), we first note that a substitution T 
unifies E iff dom(h) = dom(h') and T unifies (E' U\J ledom ( h ){h(l) — h'{l)}) and T is defined 
on (h,X) and (h',X). We also note that the degree of (E' U Uzedom(/i)W) — ^'(0)) ^ s 
smaller than the degree of E, and that Qe = Qie'u[ J {h(i)=h'(l)\) ^ i^-}- The proof of 

(2) and (3) then follows easily from the inductive hypothesis. 

Suppose that a — r is of the form t — r. To prove (1), we first note that if UNIFIER 
succeeds then either t = r oi t does not occur in r. In the first case, the degree of E' is 
clearly (to, n — 2); in the second case, the first component of the degree of [r/t]E' is at most 
to — 1. To prove (2) and (3), we use Lemma A.l and again proceed by case analysis. In 
the case that t = r, we note that the degree of E' is less than the degree of E, and that 
Q E = Q E , u {t}. In the case that t / r, we note that the degree of [r/t]E' is less than 
the degree of E, and that Q E = Q[ T /t]E' u (0 u { tne tyP e an< ^ row variables in r}. Using 
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these properties and Lemma A.l, the proofs of (2) and (3) for both cases follow from the 
inductive hypothesis. 

Suppose that a = r is of the form (h,X) = (h',NULL). To prove (1), we observe that 
if UNIFIER succeeds, then the first component of the degree of [(h 1 ,NULL)/X]E' is at 
most m - 1. To prove (2) and (3), we use Lemma A.2. We first note that the degree of 
[{h\,NULL)/X]E f is less than the degree of E, and that Q E = Q[{h u NULL)/X]E' u {%} u 
{the type and row variables in the range of hi}. To prove (2), we also note that, if there 
is a substitution that unifies E, then, since (hi, NULL) contains only type and row vari- 
ables from Q E , Lemma A.2 implies that [(h u NULL)/X}; UNIFIER([(/i!, NULL)/X](E'U 
\Ji ed om(h){K l ) - h'{l)}), Q') is defined. Using these properties and Lemma A.2, the proofs 
of (2) and (3) follow from the inductive hypothesis. 

Suppose that a = t is of the form (h, X) = (h', X'). To prove (1), we observe that if UNI- 
FIER succeeds, then the first component of the degree of V(E') is at most m— 1. To prove (2) 
and (3), we use Lemma A. 3. We first note that the degree of V(E') is less than the degree of 
E, and that Qe = Q[{h^,NULL)/x]E<^{^ e tv P e an( i row variables in the range of hi or h 2 }U 
{X, X'}. To prove (2), we also note that, if there is a substitution T that unifies E, then, 
since (hi,y) and (h2,y) contain only type and row variables from Qe, Lemma A. 3 implies 
that V;UNIFIER([(A 1 , NU LL) / X}{E'U{j ledom{h)ndom{hl) {h(l) = h'(l)}), Q')is defined. By 
the inductive hypothesis, we can deduce that this substitution is equal to T with respect to 
QU Qe, and thus this substitution is defined on (h,X) and (h',X'). Using these properties 
and Lemma A. 3, the proofs of (2) and (3) follow from the inductive hypothesis, proving the 
lemma. 

As mentioned at the beginning of the appendix, our algorithm UNIFIER corrects a bug 
in the unification algorithm of [Wan87]. Wand's algorithm uses the substitution 

[(hi,y)/x,{h 2 ,y/x')] 

instead of the substitution 

[(hi,y)/x, (h 2 , y/x% [(hi, y)/x, (h 2 , y/x')\ 

which we call V. However, applying the simpler substitution used by Wand to the set 
(E' U Uiedom(/i)ndom(/i'){^(0 = ^'(01) does not necessarily decrease the halting measure, 
since X' may occur in hi or X may occur in h 2 . We correct this difficulty in Wand's 
algorithm through our use of the substitution V. ■ 
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